Description
In the Linux kernel, the following vulnerability has been resolved:

nvme-pci: release descriptor pools on probe failure

The per-NUMA-node descriptor DMA pools are created lazily from
nvme_init_hctx_common() once the admin tag set is allocated, but they are
only destroyed in nvme_remove() via nvme_release_descriptor_pools(). Any
probe failure after the admin tag set has been allocated unwinds through
the out_disable label and nvme_pci_free_ctrl(), neither of which releases
the pools, leaking the dma_pool objects.

Release the descriptor pools in the out_disable error path. It must not
be added to nvme_pci_free_ctrl(), as that would double-free against
nvme_remove() on the normal teardown path.
Published: 2026-09-17
Score: n/a
EPSS: < 1% Very Low
KEV: No
Impact: Resource Exhaustion / Denial of Service
Action: Patch
AI Analysis

Impact

The Linux kernel NVMe PCI driver fails to free DMA descriptor pools when a probe fails after the admin tag set has been allocated; the pools are leaked as dma_pool objects. Accumulation of these leaked objects can consume kernel memory and, if exhausted, can block the system from handling new NVMe devices, effectively causing a denial of service. This is an instance of the CWE‑400: Uncontrolled Resource Consumption (resource exhaustion) flaw.

Affected Systems

All Linux kernel builds that contain the NVMe PCI driver and have not yet incorporated the patch that releases descriptor pools on probe failure are affected. The vulnerability is present across all distributions shipping the affected kernel versions, regardless of distribution, since the flaw resides in the kernel source.

Risk and Exploitability

The EPSS score is less than 1%, indicating a low probability of widespread exploitation, and the vulnerability is not listed in CISA KEV. Exploitation would likely require privileged access to perform NVMe PCI device probes, implying a local or root-level attack vector inferred from the need to trigger probe failures. Should an attacker succeed, the impact is disruption of system availability due to memory exhaustion. The CVSS score is not supplied, but based on the nature of the bug and low exploit probability the risk remains moderate but non‑negligible.

Generated by OpenCVE AI on September 20, 2026 at 01:10 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Upgrade the Linux kernel to a release that includes the commit that releases descriptor pools on probe failure (e.g., kernel version 6.8 or later depending on your distribution).
  • If a kernel update is not immediately available, manually apply the patch from the referenced commit to the kernel source and rebuild.
  • If the system does not require NVMe devices, temporarily disable or unload the NVMe PCI driver (blacklist the module) until a patched kernel is installed.

Generated by OpenCVE AI on September 20, 2026 at 01:10 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Thu, 17 Sep 2026 16:30:00 +0000

Type Values Removed Values Added
Description In the Linux kernel, the following vulnerability has been resolved: nvme-pci: release descriptor pools on probe failure The per-NUMA-node descriptor DMA pools are created lazily from nvme_init_hctx_common() once the admin tag set is allocated, but they are only destroyed in nvme_remove() via nvme_release_descriptor_pools(). Any probe failure after the admin tag set has been allocated unwinds through the out_disable label and nvme_pci_free_ctrl(), neither of which releases the pools, leaking the dma_pool objects. Release the descriptor pools in the out_disable error path. It must not be added to nvme_pci_free_ctrl(), as that would double-free against nvme_remove() on the normal teardown path.
Title nvme-pci: release descriptor pools on probe failure
First Time appeared Linux
Linux linux Kernel
CPEs cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*
Vendors & Products Linux
Linux linux Kernel
References

Subscriptions

Linux Linux Kernel
cve-icon MITRE

Status: PUBLISHED

Assigner: Linux

Published:

Updated: 2026-09-17T16:07:39.941Z

Reserved: 2026-09-11T19:38:34.794Z

Link: CVE-2026-90233

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Received

Published: 2026-09-17T17:17:19.173

Modified: 2026-09-17T17:17:19.173

Link: CVE-2026-90233

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-20T01:15:07Z

Weaknesses

No weakness.