-

CVE-2026-80821

nvmet: pci-epf: put CQ ref on create_cq mapping failure

In the Linux kernel, the following vulnerability has been resolved:

nvmet: pci-epf: put CQ ref on create_cq mapping failure

nvmet_pci_epf_create_cq() calls nvmet_cq_create(), which takes a
reference on the controller and installs the completion queue. If the
subsequent PCI address-space mapping fails or returns a too-small partial
mapping, the function jumps to err_internal / err_unmap_queue without
calling nvmet_cq_put(). The matching put in nvmet_pci_epf_delete_cq() is
gated on NVMET_PCI_EPF_Q_LIVE, which is only set after the mapping
succeeds, so teardown never releases these references. A remote PCI host
that drives Create IO CQ commands with a failing PRP1/pci_addr therefore
leaks the CQ and a controller reference on each attempt.

Drop the CQ reference on the mapping-failure paths. The err_internal and
err_unmap_queue labels are only reachable after nvmet_cq_create() has
succeeded, so this pairs the create/put correctly.
Daten sind bereitgestellt durch das CVE Programm von einer CVE Numbering Authority (CNA) (Unstrukturiert).
HerstellerLinux
≫
Produkt Linux
Default Statusunaffected
Version 0faa0fe6f90ea59b10d1b0f15ce0eb0c18eff186
Version < f31650243c1ab32394077f234685e89ed8dece84
Status affected
Version 0faa0fe6f90ea59b10d1b0f15ce0eb0c18eff186
Version < b5f97fae2503a763fa0f953abf5f121b0fef7d0d
Status affected
Version 0faa0fe6f90ea59b10d1b0f15ce0eb0c18eff186
Version < 56a7b6a6880dbabe28214ff88df8d229ca3a944a
Status affected
Version 0faa0fe6f90ea59b10d1b0f15ce0eb0c18eff186
Version < 659ae9d02cb5d72c76f74fff7441eb8fb64d8f5c
Status affected
HerstellerLinux
≫
Produkt Linux
Default Statusaffected
Version 6.14
Status affected
Version 0
Version < 6.14
Status unaffected
Version <= 6.18.*
Version 6.18.47
Status unaffected
Version <= 7.1.*
Version 7.1.11
Status unaffected
Version <= 7.2.*
Version 7.2.1
Status unaffected
Version <= *
Version 7.3-rc1
Status unaffected
VulnDex Vulnerability Enrichment
Diese Information steht angemeldeten Benutzern zur Verfügung. Login Login
Zu dieser CVE wurde keine Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 0.17% 0.063
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
Es wurden noch keine Informationen zu CWE veröffentlicht.
https://git.kernel.org/stable/c/f31650243c1ab32394077f234685e89ed8dece84
https://git.kernel.org/stable/c/b5f97fae2503a763fa0f953abf5f121b0fef7d0d
https://git.kernel.org/stable/c/56a7b6a6880dbabe28214ff88df8d229ca3a944a
https://git.kernel.org/stable/c/659ae9d02cb5d72c76f74fff7441eb8fb64d8f5c