๐Ÿ” CVE Alert

CVE-2026-89972

UNKNOWN 0.0

nvme: add missing SRCU grace period in error path

CVSS Score
0.0
EPSS Score
0.0%
EPSS Percentile
0th

In the Linux kernel, the following vulnerability has been resolved: nvme: add missing SRCU grace period in error path nvme_alloc_ns() error path at out_unlink_ns removes ns from the namespace head siblings list with list_del_rcu(&ns->siblings) but does not wait for SRCU readers before freeing the namespace struct. Multipath code iterates the head->list under srcu_read_lock() in nvme_find_path() and nvme_mpath_revalidate_paths(), so a concurrent reader can still hold a reference to ns when kfree(ns) runs. The normal removal path in nvme_ns_remove() correctly calls synchronize_srcu(&ns->head->srcu) after list_del_rcu() to wait for in-progress readers. Add the same grace period in the error path.

Vendor linux
Product linux
Ecosystems
Industries
Technology
Published Sep 16, 2026
Stay Ahead of the Next One

Get instant alerts for linux linux

Be the first to know when new unknown vulnerabilities affecting linux linux are published โ€” delivered to Slack, Telegram or Discord.

Get Free Alerts โ†’ Free ยท No credit card ยท 60 sec setup

Affected Versions

Linux / Linux
ed754e5deeb17f4e675c84e4b6c640cc7344e498 < d663944dbad81bb0e3635d7090db4713e6300858 ed754e5deeb17f4e675c84e4b6c640cc7344e498 < 76023560d60f10b4f808941163aa2975f1631683 ed754e5deeb17f4e675c84e4b6c640cc7344e498 < ef248d5de4469fb6bbaf8dbe0c4c47800080d648
Linux / Linux
4.15

References

NVD โ†— CVE.org โ†— EPSS Data โ†—
git.kernel.org: https://git.kernel.org/stable/c/d663944dbad81bb0e3635d7090db4713e6300858 git.kernel.org: https://git.kernel.org/stable/c/76023560d60f10b4f808941163aa2975f1631683 git.kernel.org: https://git.kernel.org/stable/c/ef248d5de4469fb6bbaf8dbe0c4c47800080d648