Linux Kernel Vulnerability in NVMe-RDMA Queue Processing
CVE-2026-98154
What is CVE-2026-98154?
A flaw in the Linux kernel's NVMe-RDMA queue processing was identified, where improper handling of the -EIO error could lead to double cleanup operations. In the affected process, a host path error is reported after the command has already been cleaned up, resulting in a potential vulnerability. The error handling sequence is incorrectly ordered, leading to incorrect cleanup and unmapping of the SQE DMA, which could introduce instability in the kernel's operations. Effective mitigation requires rearranging the cleanup sequence to ensure that unmapping occurs before the error is reported, thereby preventing unnecessary complications in resource management.
Affected Version(s)
Linux 62eca39722fd997e3621fc903229917b9f0fb271
Linux 62eca39722fd997e3621fc903229917b9f0fb271
Linux 62eca39722fd997e3621fc903229917b9f0fb271 < 171b993a4aed9889159df4815b6a6ba141e61975