PT-2026-98719 · Linux · Linux

CVE-2026-98056

·

Published

2026-09-25

·

Updated

2026-09-25

CVSS v3.1

7.5

High

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
In the Linux kernel, the following vulnerability has been resolved:
nvme: remove stale namespaces by NSID range during scan
nvme scan ns list() drops the stale namespaces in each gap in the reported NSID list one NSID at a time. Every iteration calls nvme find get ns() to look the namespace up and removes it if it is present. The loop runs once per NSID in the gap rather than once per namespace actually present.
NSIDs are 32-bit, so a target with a sparse NSID space can make a single gap spin the loop billions of times with nothing to remove.
watchdog: BUG: soft lockup - CPU#4 stuck for 26s! Workqueue: nvme-wq nvme scan work [nvme core] RIP: 0010: srcu read unlock+0xb/0x20 Call Trace: nvme find get ns+0x7d/0xb0 [nvme core] nvme scan ns list+0xe8/0x280 [nvme core] nvme scan work+0x18a/0x280 [nvme core] process one work+0x197/0x380 worker thread+0x2fe/0x410 kthread+0xe0/0x100
Rename nvme remove invalid namespaces() to nvme remove nsid range() and give it an open (start, end) NSID range. ctrl->namespaces is sorted by NSID, so the whole gap is dropped in a single walk that stops once end is reached. This bounds the work by the namespaces that are present instead of by the size of the gap.

Fix

Found an issue in the description? Have something to add? Feel free to write us 👾

Related Identifiers

CVE-2026-98056

Affected Products

Linux