Impact
In the NVMe‑FC subsystem of the Linux kernel, an error path in request initialization fails to unmap a previously mapped command I/O unit when the response I/O unit mapping fails. This leaves a DMA mapping leak that persists until the operation completes, potentially exhausting kernel DMA resources and causing system degradation or crashes. The vulnerability is a local kernel‑level flaw that could be triggered by any NVMe initiator device or process able to issue NVMe commands to the affected controller.
Affected Systems
All Linux kernel builds that include the NVMe‑FC subsystem, regardless of vendor, are affected because the vulnerability is present in the core kernel code. No specific kernel version is listed, so any kernel revision prior to the patch that contains the commit sequence referenced in the advisory should be considered vulnerable.
Risk and Exploitability
The EPSS score is below 1%, indicating a very low likelihood of exploitation in the wild, and the vulnerability is not currently listed in the CISA KEV catalog. The CVSS score is not provided, but the flaw permits a local attacker to exhaust kernel DMA mappings, leading to denial of service. The typical attack vector would require local privilege or the ability to issue NVMe commands to the kernel.
OpenCVE Enrichment
Debian DLA
Debian DSA