CVE-2026-72128

Summary

In the Linux kernel, the following vulnerability has been resolved:

nvmet: fix refcount leak in nvmet_sq_create()

In nvmet_sq_create(), a reference on the ctrl is taken via kref_get_unless_zero() before calling nvmet_check_sqid(). If nvmet_check_sqid() fails, the function returns the error directly without releasing the reference, leading to a leak.

Fix this by jumping to the "ctrl_put" label, which already performs the necessary nvmet_ctrl_put(ctrl). This ensures the reference is properly released on this error path.

Affected Software

VendorProductVersion RangeStatus
LinuxLinux1eb380caf5275bba1d3d6182dde1fd740f331743 < 26355295ce21cb046546085c3a81abe68160a784affected
LinuxLinux1eb380caf5275bba1d3d6182dde1fd740f331743 < fcef60ed5f714a24104eb021d6397a67955ebeffaffected
LinuxLinux1eb380caf5275bba1d3d6182dde1fd740f331743 < 34b9a83c50660148bde01cde16451dbe78369749affected
LinuxLinux6.14affected
LinuxLinux0 < 6.14unaffected
LinuxLinux6.18.40 <= 6.18.*unaffected
LinuxLinux7.1.5 <= 7.1.*unaffected
LinuxLinux7.2 <= *unaffected

Weaknesses

References