PT-2026-93613 · Linux · Linux Kernel
CVE-2026-89972
·
Published
2026-09-16
·
Updated
2026-10-05
CVSS v3.1
9.8
Critical
| Vector | AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
Linux kernel (affected versions not specified)
Description
An issue exists in the NVMe subsystem where the
nvme alloc ns() function fails to wait for Sleepable Read-Copy-Update (SRCU) readers in its error path at out unlink ns. While the function removes the namespace from the siblings list using list del rcu(&ns->siblings), it proceeds to free the namespace structure without ensuring that concurrent readers have finished. Because multipath code in nvme find path() and nvme mpath revalidate paths() iterates through the list under srcu read lock(), a reader may still hold a reference to the namespace when kfree(ns) is executed, potentially leading to a use-after-free scenario. SRCU is a synchronization mechanism that allows readers to access data without locks while writers update it.Recommendations
At the moment, there is no information about a newer version that contains a fix for this vulnerability.
Exploit
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Linux Kernel