Description
In the Linux kernel, the following vulnerability has been resolved:

nvme: add missing SRCU grace period in error path

nvme_alloc_ns() error path at out_unlink_ns removes ns from the
namespace head siblings list with list_del_rcu(&ns->siblings) but
does not wait for SRCU readers before freeing the namespace struct.
Multipath code iterates the head->list under srcu_read_lock() in
nvme_find_path() and nvme_mpath_revalidate_paths(), so a concurrent
reader can still hold a reference to ns when kfree(ns) runs.

The normal removal path in nvme_ns_remove() correctly calls
synchronize_srcu(&ns->head->srcu) after list_del_rcu() to wait for
in-progress readers. Add the same grace period in the error path.
Published: 2026-09-16
Score: 9.8 Critical
EPSS: < 1% Very Low
KEV: No
Impact: Use‑after‑free in the NVMe driver causing kernel memory corruption
Action: Immediate Patch
AI Analysis

Impact

A missing SRCU grace period in the NVMe namespace allocation error path causes the namespace structure to be freed while a reader may still be accessing it. This results in a classic use‑after‑free condition that can corrupt kernel memory and potentially allow an attacker to execute arbitrary code with kernel privileges.

Affected Systems

Any Linux system running a kernel version that contains the vulnerable NVMe code prior to the commit that introduces the SRCU grace period is affected. This includes distributions that have not yet applied the patch identified by commit 76023560d60f10b4f808941163aa2975f1631683. All Linux kernels with a vulnerable NVMe driver are at risk.

Risk and Exploitability

The CVSS score of 9.8 reflects a severe impact. The EPSS score of less than 1% indicates a low probability of current exploitation, yet the kernel‑level nature makes any successful exploit highly damaging. The vulnerability is not listed in the CISA KEV catalog. Based on the description, it is inferred that the attack could be local, but a remotely‑targeted attack might be possible if an attacker can trigger the NVMe driver via a network protocol such as iSCSI or RDMA that feeds malicious NVMe commands to the device. Successful exploitation would likely require precise timing to achieve the race condition between the error path and concurrent readers.

Generated by OpenCVE AI on September 18, 2026 at 08:05 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Upgrade the Linux kernel to a version that includes the patch adding an SRCU grace period to the NVMe error path (e.g., the kernel commit 76023560d60f10b4f808941163aa2975f1631683).
  • If a kernel upgrade cannot be performed immediately, temporarily disable NVMe multipath support or avoid using NVMe devices until the patch is applied to eliminate the race condition.
  • If a quick upgrade is not possible, manually apply the patch from the commit that introduces the SRCU synchronization to the kernel source tree and rebuild the kernel.

Generated by OpenCVE AI on September 18, 2026 at 08:05 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Sat, 03 Oct 2026 11:15:00 +0000


Fri, 18 Sep 2026 08:30:00 +0000

Type Values Removed Values Added
Weaknesses CWE-362
CWE-416

Wed, 16 Sep 2026 14:45:00 +0000

Type Values Removed Values Added
Metrics cvssV3_1

{'score': 9.8, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H'}


Wed, 16 Sep 2026 10:45:00 +0000

Type Values Removed Values Added
Description In the Linux kernel, the following vulnerability has been resolved: nvme: add missing SRCU grace period in error path nvme_alloc_ns() error path at out_unlink_ns removes ns from the namespace head siblings list with list_del_rcu(&ns->siblings) but does not wait for SRCU readers before freeing the namespace struct. Multipath code iterates the head->list under srcu_read_lock() in nvme_find_path() and nvme_mpath_revalidate_paths(), so a concurrent reader can still hold a reference to ns when kfree(ns) runs. The normal removal path in nvme_ns_remove() correctly calls synchronize_srcu(&ns->head->srcu) after list_del_rcu() to wait for in-progress readers. Add the same grace period in the error path.
Title nvme: add missing SRCU grace period in error path
First Time appeared Linux
Linux linux Kernel
CPEs cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*
Vendors & Products Linux
Linux linux Kernel
References

Subscriptions

Linux Linux Kernel
cve-icon MITRE

Status: PUBLISHED

Assigner: Linux

Published:

Updated: 2026-10-03T10:56:54.699Z

Reserved: 2026-09-11T19:38:34.778Z

Link: CVE-2026-89972

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Received

Published: 2026-09-16T11:17:07.953

Modified: 2026-10-03T11:17:45.160

Link: CVE-2026-89972

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-18T08:15:06Z

Weaknesses
  • CWE-362

    Concurrent Execution using Shared Resource with Improper Synchronization ('Race Condition')

  • CWE-416

    Use After Free