Use of uninitialized resource in Linux kernel - CVE-2026-97409
Published: September 25, 2026
Vulnerability details
The vulnerability allows a local user to disable locking correctness validation.
The vulnerability exists due to use of an uninitialized resource in __nvme_fc_abort_outstanding_ios() when error recovery aborts outstanding requests before the I/O tagset is initialized. A local user can trigger an admin request timeout during controller connection to disable locking correctness validation.
The condition occurs while the NVMe over Fibre Channel controller is in the CONNECTING state.