Description
In the Linux kernel, the following vulnerability has been resolved:

nvme-fc: unmap cmd_iu DMA on rsp_iu mapping failure in init_request

__nvme_fc_init_request() maps cmd_iu and then rsp_iu for DMA. If the
rsp_iu mapping fails, the original code only recorded the error and fell
through: it left the already-mapped cmd_iu unmapped and still marked the
op as FCPOP_STATE_IDLE before returning. Since blk-mq does not call
.exit_request() when .init_request() fails, the cmd_iu mapping is leaked
for every op whose rsp_iu mapping fails.

Jump to an error path on rsp_iu mapping failure that unmaps cmd_iu and
returns the error without marking the op idle, so it stays in the
FCPOP_STATE_UNINIT state set by the initial memset().
Published: 2026-09-17
Score: n/a
EPSS: < 1% Very Low
KEV: No
Impact: Denial of Service via resource exhaustion
Action: Apply Patch
AI Analysis

Impact

In the NVMe‑FC subsystem of the Linux kernel, an error path in request initialization fails to unmap a previously mapped command I/O unit when the response I/O unit mapping fails. This leaves a DMA mapping leak that persists until the operation completes, potentially exhausting kernel DMA resources and causing system degradation or crashes. The vulnerability is a local kernel‑level flaw that could be triggered by any NVMe initiator device or process able to issue NVMe commands to the affected controller.

Affected Systems

All Linux kernel builds that include the NVMe‑FC subsystem, regardless of vendor, are affected because the vulnerability is present in the core kernel code. No specific kernel version is listed, so any kernel revision prior to the patch that contains the commit sequence referenced in the advisory should be considered vulnerable.

Risk and Exploitability

The EPSS score is below 1%, indicating a very low likelihood of exploitation in the wild, and the vulnerability is not currently listed in the CISA KEV catalog. The CVSS score is not provided, but the flaw permits a local attacker to exhaust kernel DMA mappings, leading to denial of service. The typical attack vector would require local privilege or the ability to issue NVMe commands to the kernel.

Generated by OpenCVE AI on September 19, 2026 at 13:16 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Update the Linux kernel to a version that includes the patch referenced in the advisory, such as the commit 18c5781ed8bc2f423c26ec93e47e2057cd76a783.
  • If a kernel update cannot be applied immediately, disable or unload the nvme‑fc module to prevent the vulnerable code path from executing.
  • Regularly monitor system logs and DMA mapping counters for abnormal growth patterns that may indicate residual mapping leaks while the fix is pending.

Generated by OpenCVE AI on September 19, 2026 at 13:16 UTC.

Tracking

Sign in to view the affected projects.

Advisories
Source ID Title
Debian DLA Debian DLA DLA-4817-1 linux-6.12 security update
Debian DSA Debian DSA DSA-6528-1 linux security update
History

Sat, 19 Sep 2026 13:45:00 +0000

Type Values Removed Values Added
Weaknesses CWE-789

Thu, 17 Sep 2026 16:30:00 +0000

Type Values Removed Values Added
Description In the Linux kernel, the following vulnerability has been resolved: nvme-fc: unmap cmd_iu DMA on rsp_iu mapping failure in init_request __nvme_fc_init_request() maps cmd_iu and then rsp_iu for DMA. If the rsp_iu mapping fails, the original code only recorded the error and fell through: it left the already-mapped cmd_iu unmapped and still marked the op as FCPOP_STATE_IDLE before returning. Since blk-mq does not call .exit_request() when .init_request() fails, the cmd_iu mapping is leaked for every op whose rsp_iu mapping fails. Jump to an error path on rsp_iu mapping failure that unmaps cmd_iu and returns the error without marking the op idle, so it stays in the FCPOP_STATE_UNINIT state set by the initial memset().
Title nvme-fc: unmap cmd_iu DMA on rsp_iu mapping failure in init_request
First Time appeared Linux
Linux linux Kernel
CPEs cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*
Vendors & Products Linux
Linux linux Kernel
References

Subscriptions

Linux Linux Kernel
cve-icon MITRE

Status: PUBLISHED

Assigner: Linux

Published:

Updated: 2026-09-17T16:09:38.077Z

Reserved: 2026-09-11T19:38:34.812Z

Link: CVE-2026-90411

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Received

Published: 2026-09-17T17:17:41.077

Modified: 2026-09-17T17:17:41.077

Link: CVE-2026-90411

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-19T13:30:13Z

Weaknesses
  • CWE-789

    Memory Allocation with Excessive Size Value