Executive brief
A race condition vulnerability was identified in the Linux kernel's NVMe-over-PCI driver. This component is responsible for managing high-speed storage devices (SSDs) connected via PCI Express. An exploit could cause a system crash or instability (kernel warning/panic) during specific hardware reset or timeout events, potentially leading to a denial of service for the affected system.
Technical details
A race condition exists in nvme_poll_irqdisable() within the nvme-pci driver. The vulnerability occurs because the code calls pci_irq_vector() twice—once for disable_irq() and once for enable_irq(). If a concurrent nvme_reset_work() task disables the PCI device (setting msix_enabled to 0) between these two calls, the first call may return an MSI-X IRQ while the second returns an INTx IRQ. This results in an 'unbalanced enable' warning or kernel panic because the system attempts to enable an IRQ that was never disabled. The fix involves caching the IRQ number in a local variable to ensure both operations target the same identifier. Patches are available in various stable kernel branches.
Affected products
- Linux Linux kernel 5.7 to 6.1.167, 6.2 to 6.6.130, 6.7 to 6.12.78, 6.13 to 6.18.19, 6.19 to 6.19.9, 7.0-rc1 to 7.0-rc3
Timeline
- 2026-03-07: disclosed: Vulnerability reported by Sungwoo Kim
- 2026-03-25: patched: Fix committed to stable kernel trees
- 2026-05-08: advisory: CVE-2026-43448 published
References
- https://git.kernel.org/stable/c/265dbc9bc33c29f60f90be3e0afe1c4067ebb70b
- https://git.kernel.org/stable/c/628773eba024d1107cc9ec157a682cbb42ac912a
- https://git.kernel.org/stable/c/843e913cef4e33723663a899727f685a95ab53fe
- https://git.kernel.org/stable/c/b56c49897bdac5cb49e3495ef421c391628ee9bb
- https://git.kernel.org/stable/c/e311d84c62eb76e025e11a44155b402e55950b83
- https://git.kernel.org/stable/c/fc71f409b22ca831a9f87a2712eaa09ef2bb4a5e