CVE-2026-23360
In the Linux kernel, the following vulnerability has been resolved: nvme: fix admin queue leak on controller reset When nvme_alloc_admin_tag_set() is called during a controller reset, a previous admin queue may still exist.
Does this matter?
Lower severity and a low EPSS score (0.12%). Track it; it rarely justifies an emergency change on its own.
Description
In the Linux kernel, the following vulnerability has been resolved: nvme: fix admin queue leak on controller reset When nvme_alloc_admin_tag_set() is called during a controller reset, a previous admin queue may still exist. Release it properly before allocating a new one to avoid orphaning the old queue. This fixes a regression introduced by commit 03b3bcd319b3 ("nvme: fix admin request_queue lifetime").
- CVSS 3.1
- 5.5 MEDIUMCVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
- EPSS
- 0.12% probability · 2th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-401
- Affected
- linux/linux kernel
- Source
- 416baaa9-dc9f-4396-8d5f-8c081fb06d67
References
- https://git.kernel.org/stable/c/089a6f17881a82c6c6e05f8564a867be0767eadePatch
- https://git.kernel.org/stable/c/2efbc838a26d3da72d8fe05770bdf869d4ca3ac5Patch
- https://git.kernel.org/stable/c/64f87b96de0e645a4c066c7cffd753f334446db6Patch
- https://git.kernel.org/stable/c/6e28bab900e40e4d610b04f9f82e01983d8fb356Patch
- https://git.kernel.org/stable/c/8eb2b3cdcd9b6631b94b82c1f4f6bc32b40d942fPatch
- https://git.kernel.org/stable/c/b84bb7bd913d8ca2f976ee6faf4a174f91c02b8dPatch
- https://git.kernel.org/stable/c/e159eb852aeee95443a9458ecb7d072bbb689913Patch
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.