Thread Safety Vulnerability in Linux Kernel Affecting nvme Product
CVE-2026-80862

Currently unrated

Key Information:

Vendor

Linux

Status
Vendor
CVE Published:
4 September 2026

What is CVE-2026-80862?

A thread safety vulnerability in the Linux kernel's nvme implementation can lead to incorrect reference counting of backstore pages due to improper use of page_frag_cache. This vulnerability occurs when block devices are created in parallel threads, resulting in the potential for premature freeing of memory and random system panics. The issue has been addressed by serializing the usage of page_frag_cache to enhance safety and ensure correct memory management during data transmission.

Affected Version(s)

Linux 4e893ca8117022de68ce1b61c0309e3d17bb8a25

Linux 4e893ca8117022de68ce1b61c0309e3d17bb8a25 < 64561afb42d8390695bf810d9bbd087cbca00291

Linux 4e893ca8117022de68ce1b61c0309e3d17bb8a25 < 0a9750263ffacbbd2048a391fd4bd22e2146c57d

References

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.