Impact
The vulnerability occurs in the Linux kernel’s NVMe target authentication subsystem. The nvmet_auth_sq_free function attempts to cancel a delayed auth_expired_work item, but if the work has already begun, the cancellation does not wait; as a result, the subsequent teardown may free or reuse the request queue while the delayed work routine still refers to it. This race can cause the kernel to read or write memory that has been freed, potentially crashing the system or allowing an attacker to execute arbitrary code.
Affected Systems
All Linux kernel releases that have not incorporated the pending patch are affected. The listing indicates that the flaw is present in the generic Linux kernel (cpe:2.3:o:linux:linux_kernel:*). No specific version range is given, so any kernel that has the nvmet_auth subsystem and the vulnerable teardown logic remains at risk until updated.
Risk and Exploitability
The flaw carries a CVSS score of 9.8, signalling a critical vulnerability. The EPSS score is reported as less than 1%, indicating a low current exploit probability, and the issue is not yet present in the CISA KEV catalog. Exploitation would likely require privileged or local access to send crafted NVMe commands that trigger the teardown during an active auth_expired_work instance. Attackers could use this race to cause a kernel panic or potentially gain arbitrary code execution if memory corruption allows control flow hijack.
OpenCVE Enrichment
Debian DLA
Debian DSA