๐Ÿ” CVE Alert

CVE-2026-80821

UNKNOWN 0.0

nvmet: pci-epf: put CQ ref on create_cq mapping failure

CVSS Score
0.0
EPSS Score
0.0%
EPSS Percentile
0th

In the Linux kernel, the following vulnerability has been resolved: nvmet: pci-epf: put CQ ref on create_cq mapping failure nvmet_pci_epf_create_cq() calls nvmet_cq_create(), which takes a reference on the controller and installs the completion queue. If the subsequent PCI address-space mapping fails or returns a too-small partial mapping, the function jumps to err_internal / err_unmap_queue without calling nvmet_cq_put(). The matching put in nvmet_pci_epf_delete_cq() is gated on NVMET_PCI_EPF_Q_LIVE, which is only set after the mapping succeeds, so teardown never releases these references. A remote PCI host that drives Create IO CQ commands with a failing PRP1/pci_addr therefore leaks the CQ and a controller reference on each attempt. Drop the CQ reference on the mapping-failure paths. The err_internal and err_unmap_queue labels are only reachable after nvmet_cq_create() has succeeded, so this pairs the create/put correctly.

Vendor linux
Product linux
Ecosystems
Industries
Technology
Published Sep 4, 2026
Last Updated Sep 4, 2026
Stay Ahead of the Next One

Get instant alerts for linux linux

Be the first to know when new unknown vulnerabilities affecting linux linux are published โ€” delivered to Slack, Telegram or Discord.

Get Free Alerts โ†’ Free ยท No credit card ยท 60 sec setup

Affected Versions

Linux / Linux
0faa0fe6f90ea59b10d1b0f15ce0eb0c18eff186 < f31650243c1ab32394077f234685e89ed8dece84 0faa0fe6f90ea59b10d1b0f15ce0eb0c18eff186 < b5f97fae2503a763fa0f953abf5f121b0fef7d0d 0faa0fe6f90ea59b10d1b0f15ce0eb0c18eff186 < 56a7b6a6880dbabe28214ff88df8d229ca3a944a 0faa0fe6f90ea59b10d1b0f15ce0eb0c18eff186 < 659ae9d02cb5d72c76f74fff7441eb8fb64d8f5c
Linux / Linux
6.14

References

NVD โ†— CVE.org โ†— EPSS Data โ†—
git.kernel.org: https://git.kernel.org/stable/c/f31650243c1ab32394077f234685e89ed8dece84 git.kernel.org: https://git.kernel.org/stable/c/b5f97fae2503a763fa0f953abf5f121b0fef7d0d git.kernel.org: https://git.kernel.org/stable/c/56a7b6a6880dbabe28214ff88df8d229ca3a944a git.kernel.org: https://git.kernel.org/stable/c/659ae9d02cb5d72c76f74fff7441eb8fb64d8f5c