Impact
The vulnerability is caused by a double free of NVMe–Fabric options when nvme_add_ctrl() fails. The error path in nvme_fc_init_ctrl() does not clear the options pointer, so the transport’s free function later frees the already freed memory. This results in a use‑after‑free and kernel memory corruption, which can trigger a kernel crash or a KASAN error. The condition is triggered when dev_set_name() cannot allocate memory, such as under memory pressure or fault injection.
Affected Systems
All Linux kernel releases that include the nvme‑fc driver code before the commit that clears the options pointer on every error exit are affected. The fix was added in the commit identified by the hashes linked in the references. Systems running kernels that do not contain that commit are vulnerable; authors of patched kernels should verify the presence of the commit that moves the error exit to clear the pointer.
Risk and Exploitability
The CVSS score of 7.5 indicates medium‑high risk, while the EPSS score of less than 1 % suggests that exploitation is unlikely at present. The vulnerability is not listed in the CISA KEV catalog. The likely attack vector requires a local process that can cause nvme_add_ctrl() failures, for example by inducing memory pressure or injecting faults. Successful exploitation would lead to kernel memory corruption and a system crash, as demonstrated by KASAN reports.
OpenCVE Enrichment
Debian DLA
Debian DSA