CVE-2026-64321
N/A
N/A
Summary
In the Linux kernel, the following vulnerability has been resolved:
nvme: target: rdma: fix ndev refcount leak on queue connect
nvmet_rdma_queue_connect() calls nvmet_rdma_find_get_device() which acquires a reference on the returned ndev via kref_get(). On the path where the host queue backlog is exceeded and the function returns NVME_SC_CONNECT_CTRL_BUSY, reference of ndev is not released, leaking the kref.
Fix this by adding a goto to the existing put_device label before the early return.
Affected Software
| Vendor | Product | Version Range | Status |
|---|---|---|---|
| Linux | Linux | 31deaeb11ba7a885116c9c30892b9f763c04d59c < d65fe42820b890a6a4644de0a95a812471f79ad3 | affected |
| Linux | Linux | 31deaeb11ba7a885116c9c30892b9f763c04d59c < a8803c4f0ac3fa7df5551bbb5a8800c434a94357 | affected |
| Linux | Linux | 31deaeb11ba7a885116c9c30892b9f763c04d59c < 5828517d17eda27f21d29ea14800c9e0a57bad11 | affected |
| Linux | Linux | 31deaeb11ba7a885116c9c30892b9f763c04d59c < badc53620fe813b3a9f727ef9526f98567c2c898 | affected |
| Linux | Linux | 6.8 | affected |
| Linux | Linux | 0 < 6.8 | unaffected |
| Linux | Linux | 6.12.96 <= 6.12.* | unaffected |
| Linux | Linux | 6.18.39 <= 6.18.* | unaffected |
| Linux | Linux | 7.1.4 <= 7.1.* | unaffected |
| Linux | Linux | 7.2-rc1 <= * | unaffected |
Weaknesses
References
- https://git.kernel.org/stable/c/d65fe42820b890a6a4644de0a95a812471f79ad3
- https://git.kernel.org/stable/c/a8803c4f0ac3fa7df5551bbb5a8800c434a94357
- https://git.kernel.org/stable/c/5828517d17eda27f21d29ea14800c9e0a57bad11
- https://git.kernel.org/stable/c/badc53620fe813b3a9f727ef9526f98567c2c898
Feedback
Was this page helpful?
Glad to hear it! Please tell us how we can improve.
Sorry to hear that. Please tell us how we can improve.