CVE-2026-64321

Summary

In the Linux kernel, the following vulnerability has been resolved:

nvme: target: rdma: fix ndev refcount leak on queue connect

nvmet_rdma_queue_connect() calls nvmet_rdma_find_get_device() which acquires a reference on the returned ndev via kref_get(). On the path where the host queue backlog is exceeded and the function returns NVME_SC_CONNECT_CTRL_BUSY, reference of ndev is not released, leaking the kref.

Fix this by adding a goto to the existing put_device label before the early return.

Affected Software

VendorProductVersion RangeStatus
LinuxLinux31deaeb11ba7a885116c9c30892b9f763c04d59c < d65fe42820b890a6a4644de0a95a812471f79ad3affected
LinuxLinux31deaeb11ba7a885116c9c30892b9f763c04d59c < a8803c4f0ac3fa7df5551bbb5a8800c434a94357affected
LinuxLinux31deaeb11ba7a885116c9c30892b9f763c04d59c < 5828517d17eda27f21d29ea14800c9e0a57bad11affected
LinuxLinux31deaeb11ba7a885116c9c30892b9f763c04d59c < badc53620fe813b3a9f727ef9526f98567c2c898affected
LinuxLinux6.8affected
LinuxLinux0 < 6.8unaffected
LinuxLinux6.12.96 <= 6.12.*unaffected
LinuxLinux6.18.39 <= 6.18.*unaffected
LinuxLinux7.1.4 <= 7.1.*unaffected
LinuxLinux7.2-rc1 <= *unaffected

Weaknesses

References