Missing Release of Resource after Effective Lifetime in Linux kernel - CVE-2026-98152
Published: September 28, 2026
Vulnerability details
The vulnerability allows a remote attacker to cause a denial of service.
The vulnerability exists due to missing release of resources in the nvmet_rdma_queue_connect function when handling an RDMA connection while pending disconnecting queues exceed the backlog limit. A remote attacker can initiate a connection under this condition to cause a denial of service.
Affected software
How to mitigate CVE-2026-98152
External References
- https://git.kernel.org/stable/c/186414a6a1a34e081b07e8873622f90402346235
- https://git.kernel.org/stable/c/287420cde9d6669abcd2878c344db67423eb7df6
- https://git.kernel.org/stable/c/32e598324edc3ebb1ac9362d5b9fc30ce0de4873
- https://git.kernel.org/stable/c/4f7cf573cdf0ee857448b9b1967d686b07c71e7d
- https://git.kernel.org/stable/c/60d56bf0b14d3c545bacb9aeef92a7e6f2cf0caa
- https://git.kernel.org/stable/c/e48f9d1076f8c62c3969588d638602b94aaeff12
- https://git.kernel.org/stable/c/fb1ed67788e21832b614c23767a088c08cfdd2f2