Description
In the Linux kernel, the following vulnerability has been resolved:

nvmet: fix max_qid race between configfs and controller allocation

The function nvmet_subsys_attr_qid_max_store() can race against
nvmet_alloc_ctrl() when a subsystem's max_qid limit is modified.

Suppose max_qid is currently 64. If nvmet_alloc_ctrl() executes:
ctrl->sqs = kzalloc_objs(struct nvmet_sq *, subsys->max_qid + 1);
and at this exact point, a userspace process changes max_qid to 128,
nvmet_subsys_attr_qid_max_store() will set the new max_qid value. It
attempts to delete active controllers to force a reconnect, but the
new controller won't be deleted because it hasn't been added to the
subsys->ctrls list yet.

nvmet_alloc_ctrl() then proceeds and adds the new controller to the
subsys->ctrls list. Later, when nvmet_install_queue() is called, it
will see max_qid set to 128, but the memory allocated for sqs is only
sized for 64 entries. This results in a KASAN out-of-bounds warning
and potential memory corruptions.

Fix this by protecting the queue allocations and list insertion in
nvmet_alloc_ctrl() with down_read(&nvmet_config_sem). Because
nvmet_subsys_attr_qid_max_store() acquires down_write(&nvmet_config_sem)
to modify the attribute, this safely prevents the configfs writer from
modifying max_qid during controller creation.

Copy the max_qid from the subsystem to the controller's structure
during the allocation; ctrl->max_qid never changes as long as the
controller remains in LIVE state, so this will prevent similar race
conditions.
Published: 2026-09-17
Score: n/a
EPSS: < 1% Very Low
KEV: No
Impact: Kernel memory corruption
Action: Immediate Patch
AI Analysis

Impact

The Linux kernel contains a race condition in the NVMe‑over‑TCP driver. A user process can change the subsystem maximum queue ID value while a controller is being allocated, causing the allocation to use a smaller buffer than the new limit. This triggers a KASAN out‑of‑bounds warning and can lead to memory corruption in kernel space. Because the corruption occurs in privileged kernel memory, it can be leveraged to gain additional privileges or crash the system. The weakness is a classic race condition that corrupts shared state.

Affected Systems

All Linux kernel builds that include the nvmet subsystem are potentially affected. No specific kernel versions are listed, so any kernel with the vulnerable driver code may be impacted. The vulnerability was identified from Linux kernel source changes and documented by the Linux CNA.

Risk and Exploitability

The EPSS score is below 1%, indicating a low probability of exploitation in the wild, and the vulnerability is not currently listed in the CISA KEV catalog. However, the attack requires only local access that can modify configfs entries, which is often achievable by a user with write access to the NVMe configuration filesystem. Once the race is triggered, the kernel memory corruption can lead to privilege escalation or denial of service. The vulnerability does not appear to be exploitable remotely without local interference. Risk is moderate due to the potential impact but low exploitation likelihood.

Generated by OpenCVE AI on September 19, 2026 at 03:18 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Upgrade the kernel to a version that contains the fix applied by the patch ref. 2c23fc9 and f1a8846
  • Rebuild the kernel from the updated source if using a custom configuration
  • If an immediate update is unavailable, disable writing to nvmet configfs or restart the nvmet daemon to prevent concurrent modifications during controller allocation

Generated by OpenCVE AI on September 19, 2026 at 03:18 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Sat, 19 Sep 2026 03:45:00 +0000

Type Values Removed Values Added
Weaknesses CWE-362
CWE-788

Thu, 17 Sep 2026 16:30:00 +0000

Type Values Removed Values Added
Description In the Linux kernel, the following vulnerability has been resolved: nvmet: fix max_qid race between configfs and controller allocation The function nvmet_subsys_attr_qid_max_store() can race against nvmet_alloc_ctrl() when a subsystem's max_qid limit is modified. Suppose max_qid is currently 64. If nvmet_alloc_ctrl() executes: ctrl->sqs = kzalloc_objs(struct nvmet_sq *, subsys->max_qid + 1); and at this exact point, a userspace process changes max_qid to 128, nvmet_subsys_attr_qid_max_store() will set the new max_qid value. It attempts to delete active controllers to force a reconnect, but the new controller won't be deleted because it hasn't been added to the subsys->ctrls list yet. nvmet_alloc_ctrl() then proceeds and adds the new controller to the subsys->ctrls list. Later, when nvmet_install_queue() is called, it will see max_qid set to 128, but the memory allocated for sqs is only sized for 64 entries. This results in a KASAN out-of-bounds warning and potential memory corruptions. Fix this by protecting the queue allocations and list insertion in nvmet_alloc_ctrl() with down_read(&nvmet_config_sem). Because nvmet_subsys_attr_qid_max_store() acquires down_write(&nvmet_config_sem) to modify the attribute, this safely prevents the configfs writer from modifying max_qid during controller creation. Copy the max_qid from the subsystem to the controller's structure during the allocation; ctrl->max_qid never changes as long as the controller remains in LIVE state, so this will prevent similar race conditions.
Title nvmet: fix max_qid race between configfs and controller allocation
First Time appeared Linux
Linux linux Kernel
CPEs cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*
Vendors & Products Linux
Linux linux Kernel
References

Subscriptions

Linux Linux Kernel
cve-icon MITRE

Status: PUBLISHED

Assigner: Linux

Published:

Updated: 2026-09-17T16:07:22.173Z

Reserved: 2026-09-11T19:38:34.793Z

Link: CVE-2026-90206

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Received

Published: 2026-09-17T17:17:15.700

Modified: 2026-09-17T17:17:15.700

Link: CVE-2026-90206

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-19T03:30:18Z

Weaknesses
  • CWE-362

    Concurrent Execution using Shared Resource with Improper Synchronization ('Race Condition')

  • CWE-788

    Access of Memory Location After End of Buffer