Linux Kernel Vulnerability in NVMe-RDMA Queue Processing
CVE-2026-98154

Currently unrated

Key Information:

Vendor

Linux

Status
Vendor
CVE Published:
25 September 2026

What is CVE-2026-98154?

A flaw in the Linux kernel's NVMe-RDMA queue processing was identified, where improper handling of the -EIO error could lead to double cleanup operations. In the affected process, a host path error is reported after the command has already been cleaned up, resulting in a potential vulnerability. The error handling sequence is incorrectly ordered, leading to incorrect cleanup and unmapping of the SQE DMA, which could introduce instability in the kernel's operations. Effective mitigation requires rearranging the cleanup sequence to ensure that unmapping occurs before the error is reported, thereby preventing unnecessary complications in resource management.

Affected Version(s)

Linux 62eca39722fd997e3621fc903229917b9f0fb271

Linux 62eca39722fd997e3621fc903229917b9f0fb271

Linux 62eca39722fd997e3621fc903229917b9f0fb271 < 171b993a4aed9889159df4815b6a6ba141e61975

References

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.