← Back to search

CVE-2026-89970

9.8 CRITICAL

Published 2026-09-16 · Updated 2026-09-16

AI risk analysis

Summary
This vulnerability in the Linux kernel's NVMe over Fabrics (NVMe-oF) authentication mechanism allows an attacker to prematurely free or reuse a queue, leading to potential data corruption or system instability.
Exploitability
Exploitation requires access to the affected NVMe-oF environment and knowledge of the specific SQ teardown process. The attacker must be able to trigger the SQ teardown while the authentication work is in progress.
Blast radius
If exploited, the vulnerability could lead to data corruption, system crashes, or other severe consequences, impacting the integrity and availability of the storage system.
Detection
No reliable host or network indicator is derivable from the published description.
Prioritized remediation
Upgrade to the fixed version 5.19-rc1 or later.
kernelstorageauthentication

Analysis generated locally by qwen2.5:7b-instruct (no data left the box). AI-assisted — verify against primary sources before acting.

NVD description

In the Linux kernel, the following vulnerability has been resolved: nvmet-auth: Synchronize timeout work during SQ teardown nvmet_auth_sq_free() cancels auth_expired_work with cancel_delayed_work(). If the work has already started, cancellation does not wait for the callback. Transport teardown can consequently free or reuse the queue containing struct nvmet_sq while nvmet_auth_expired_work() still accesses that SQ. Add a teardown-specific helper that synchronously drains the delayed work before freeing authentication state, and use it from nvmet_sq_destroy(). Keep the non-synchronous helper for in-band authentication state cleanup, where the SQ owner remains alive.

CVSS vector

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

All references

Source data: NVD (nvd.nist.gov), public domain. Exploit-DB.ai adds local AI analysis for defensive use only.

Related CVEs

Related by shared AI tags and CWE weakness class. Browse the full archive.