PT-2026-93613 · Linux · Linux Kernel

CVE-2026-89972

·

Published

2026-09-16

·

Updated

2026-10-05

CVSS v3.1

9.8

Critical

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Linux kernel (affected versions not specified)
Description An issue exists in the NVMe subsystem where the nvme alloc ns() function fails to wait for Sleepable Read-Copy-Update (SRCU) readers in its error path at out unlink ns. While the function removes the namespace from the siblings list using list del rcu(&ns->siblings), it proceeds to free the namespace structure without ensuring that concurrent readers have finished. Because multipath code in nvme find path() and nvme mpath revalidate paths() iterates through the list under srcu read lock(), a reader may still hold a reference to the namespace when kfree(ns) is executed, potentially leading to a use-after-free scenario. SRCU is a synchronization mechanism that allows readers to access data without locks while writers update it.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Exploit

Found an issue in the description? Have something to add? Feel free to write us 👾

Related Identifiers

ALSA-2026:75746
ALSA-2026:75747
AZL-101552
CVE-2026-89972
OPENSUSE-SU-2026:11880-1

Affected Products

Linux Kernel