Operation on a Resource after Expiration or Release in Linux kernel - CVE-2026-98154
Published: September 28, 2026
Vulnerability details
The vulnerability allows a local user to compromise confidentiality, integrity, and availability.
The vulnerability exists due to improper cleanup of completed requests in the nvme_rdma_queue_rq function when handling an -EIO error in the NVMe RDMA queue request path. A local user can trigger an -EIO error during queue request processing to compromise confidentiality, integrity, and availability.