9.8

CVE-2026-89970

nvmet-auth: Synchronize timeout work during SQ teardown

In the Linux kernel, the following vulnerability has been resolved:

nvmet-auth: Synchronize timeout work during SQ teardown

nvmet_auth_sq_free() cancels auth_expired_work with
cancel_delayed_work(). If the work has already started, cancellation does
not wait for the callback. Transport teardown can consequently free or
reuse the queue containing struct nvmet_sq while
nvmet_auth_expired_work() still accesses that SQ.

Add a teardown-specific helper that synchronously drains the delayed work
before freeing authentication state, and use it from nvmet_sq_destroy().
Keep the non-synchronous helper for in-band authentication state cleanup,
where the SQ owner remains alive.
Daten sind bereitgestellt durch das CVE Programm von einer CVE Numbering Authority (CNA) (Unstrukturiert).
HerstellerLinux
≫
Produkt Linux
Default Statusunaffected
Version 1a70200f404ae210b4f0334e3936e84f8edb6bc8
Version < 664022fa1c93f4eba09ef5ee02411b9709dd7a93
Status affected
Version 1a70200f404ae210b4f0334e3936e84f8edb6bc8
Version < c3c126a6142a1335bc8c34a5607c39cf01daf295
Status affected
Version 1a70200f404ae210b4f0334e3936e84f8edb6bc8
Version < c17c87bde6d6f5252a6a6f0a94b2430164aa28d5
Status affected
Version 1a70200f404ae210b4f0334e3936e84f8edb6bc8
Version < 7555ddd60af72df2862dd8f9b730a9848577edda
Status affected
Version 1a70200f404ae210b4f0334e3936e84f8edb6bc8
Version < eb4f9127a2b8a152743f1ee597627e2f69cb54fe
Status affected
Version 1a70200f404ae210b4f0334e3936e84f8edb6bc8
Version < eaa948c0e19b1bb2d93262207bca0c3d19cc3406
Status affected
HerstellerLinux
≫
Produkt Linux
Default Statusaffected
Version 6.0
Status affected
Version 0
Version < 6.0
Status unaffected
Version <= 6.1.*
Version 6.1.188
Status unaffected
Version <= 6.6.*
Version 6.6.157
Status unaffected
Version <= 6.12.*
Version 6.12.110
Status unaffected
Version <= 6.18.*
Version 6.18.51
Status unaffected
Version <= 7.2.*
Version 7.2.5
Status unaffected
Version <= *
Version 7.3-rc2
Status unaffected
VulnDex Vulnerability Enrichment
Diese Information steht angemeldeten Benutzern zur Verfügung. Login Login
Zu dieser CVE wurde keine Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 0.78% 0.544
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
416baaa9-dc9f-4396-8d5f-8c081fb06d67 9.8 3.9 5.9
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Es wurden noch keine Informationen zu CWE veröffentlicht.
https://git.kernel.org/stable/c/664022fa1c93f4eba09ef5ee02411b9709dd7a93
https://git.kernel.org/stable/c/c3c126a6142a1335bc8c34a5607c39cf01daf295
https://git.kernel.org/stable/c/c17c87bde6d6f5252a6a6f0a94b2430164aa28d5
https://git.kernel.org/stable/c/7555ddd60af72df2862dd8f9b730a9848577edda
https://git.kernel.org/stable/c/eb4f9127a2b8a152743f1ee597627e2f69cb54fe
https://git.kernel.org/stable/c/eaa948c0e19b1bb2d93262207bca0c3d19cc3406