Impact
The Linux kernel NVMe PCI driver fails to free DMA descriptor pools when a probe fails after the admin tag set has been allocated; the pools are leaked as dma_pool objects. Accumulation of these leaked objects can consume kernel memory and, if exhausted, can block the system from handling new NVMe devices, effectively causing a denial of service. This is an instance of the CWE‑400: Uncontrolled Resource Consumption (resource exhaustion) flaw.
Affected Systems
All Linux kernel builds that contain the NVMe PCI driver and have not yet incorporated the patch that releases descriptor pools on probe failure are affected. The vulnerability is present across all distributions shipping the affected kernel versions, regardless of distribution, since the flaw resides in the kernel source.
Risk and Exploitability
The EPSS score is less than 1%, indicating a low probability of widespread exploitation, and the vulnerability is not listed in CISA KEV. Exploitation would likely require privileged access to perform NVMe PCI device probes, implying a local or root-level attack vector inferred from the need to trigger probe failures. Should an attacker succeed, the impact is disruption of system availability due to memory exhaustion. The CVSS score is not supplied, but based on the nature of the bug and low exploit probability the risk remains moderate but non‑negligible.
OpenCVE Enrichment