Description
In the Linux kernel, the following vulnerability has been resolved:

nvmet-auth: Synchronize timeout work during SQ teardown

nvmet_auth_sq_free() cancels auth_expired_work with
cancel_delayed_work(). If the work has already started, cancellation does
not wait for the callback. Transport teardown can consequently free or
reuse the queue containing struct nvmet_sq while
nvmet_auth_expired_work() still accesses that SQ.

Add a teardown-specific helper that synchronously drains the delayed work
before freeing authentication state, and use it from nvmet_sq_destroy().
Keep the non-synchronous helper for in-band authentication state cleanup,
where the SQ owner remains alive.
Published: 2026-09-16
Score: 9.8 Critical
EPSS: < 1% Very Low
KEV: No
Impact: Use After Free leading to kernel crash or arbitrary execution
Action: Immediate Patch
AI Analysis

Impact

The vulnerability occurs in the Linux kernel’s NVMe target authentication subsystem. The nvmet_auth_sq_free function attempts to cancel a delayed auth_expired_work item, but if the work has already begun, the cancellation does not wait; as a result, the subsequent teardown may free or reuse the request queue while the delayed work routine still refers to it. This race can cause the kernel to read or write memory that has been freed, potentially crashing the system or allowing an attacker to execute arbitrary code.

Affected Systems

All Linux kernel releases that have not incorporated the pending patch are affected. The listing indicates that the flaw is present in the generic Linux kernel (cpe:2.3:o:linux:linux_kernel:*). No specific version range is given, so any kernel that has the nvmet_auth subsystem and the vulnerable teardown logic remains at risk until updated.

Risk and Exploitability

The flaw carries a CVSS score of 9.8, signalling a critical vulnerability. The EPSS score is reported as less than 1%, indicating a low current exploit probability, and the issue is not yet present in the CISA KEV catalog. Exploitation would likely require privileged or local access to send crafted NVMe commands that trigger the teardown during an active auth_expired_work instance. Attackers could use this race to cause a kernel panic or potentially gain arbitrary code execution if memory corruption allows control flow hijack.

Generated by OpenCVE AI on September 18, 2026 at 04:08 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Apply the latest kernel release that includes the fix for the nvmet-auth race condition, or backport the patch from the Linux kernel git commit list provided in the references.
  • If upgrading the kernel cannot be performed immediately, disable NVMe authentication features or limit access to the NVMe device to trusted hosts, thereby preventing the race condition from occurring.
  • After applying the patch or disabling the feature, monitor kernel logs (e.g., dmesg) for signs of NVMe authentication errors or crashes to confirm that the race has been eliminated.

Generated by OpenCVE AI on September 18, 2026 at 04:08 UTC.

Tracking

Sign in to view the affected projects.

Advisories
Source ID Title
Debian DLA Debian DLA DLA-4817-1 linux-6.12 security update
Debian DSA Debian DSA DSA-6528-1 linux security update
History

Fri, 18 Sep 2026 04:30:00 +0000

Type Values Removed Values Added
Weaknesses CWE-416

Wed, 16 Sep 2026 14:45:00 +0000

Type Values Removed Values Added
Metrics cvssV3_1

{'score': 9.8, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H'}


Wed, 16 Sep 2026 10:45:00 +0000

Type Values Removed Values Added
Description In the Linux kernel, the following vulnerability has been resolved: nvmet-auth: Synchronize timeout work during SQ teardown nvmet_auth_sq_free() cancels auth_expired_work with cancel_delayed_work(). If the work has already started, cancellation does not wait for the callback. Transport teardown can consequently free or reuse the queue containing struct nvmet_sq while nvmet_auth_expired_work() still accesses that SQ. Add a teardown-specific helper that synchronously drains the delayed work before freeing authentication state, and use it from nvmet_sq_destroy(). Keep the non-synchronous helper for in-band authentication state cleanup, where the SQ owner remains alive.
Title nvmet-auth: Synchronize timeout work during SQ teardown
First Time appeared Linux
Linux linux Kernel
CPEs cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*
Vendors & Products Linux
Linux linux Kernel
References

Subscriptions

Linux Linux Kernel
cve-icon MITRE

Status: PUBLISHED

Assigner: Linux

Published:

Updated: 2026-09-16T14:40:49.745Z

Reserved: 2026-09-11T19:38:34.778Z

Link: CVE-2026-89970

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Received

Published: 2026-09-16T11:17:07.660

Modified: 2026-09-16T15:18:21.387

Link: CVE-2026-89970

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-19T18:15:02Z

Weaknesses