Junglewise Threat Intelligence

CVE-2026-46135: Linux Kernel nvmet-tcp race condition in queue teardown

CVE-2026-46135 · Severity: info · CVSS 0 · Published 2026-05-28

Technologies: Linux Kernel. Vendors: Linux.

Executive brief

A race condition vulnerability was identified in the Linux kernel's NVMe-over-TCP target driver, which manages high-speed storage networking. If a remote host connects and then immediately disconnects, it can trigger a synchronization error that leads to a system crash or memory corruption (double-free). This could potentially disrupt storage services or impact the stability of servers acting as NVMe storage targets.

Technical details

A race condition exists in the nvmet-tcp driver between Initialization Connection Request (ICReq) handling and queue teardown. Specifically, nvmet_tcp_handle_icreq() updates the queue state after sending a response without proper serialization against the teardown process. If a host closes a connection immediately after an ICReq, the teardown may start in softirq context, setting the state to DISCONNECTING. However, io_work may later overwrite this state to LIVE or FAILED, bypassing state guards and allowing a second kref_put() to be issued on an already released queue. This results in a double-release of the queue reference. The fix involves serializing state transitions using state_lock and implementing a bailout mechanism if teardown has already commenced.

Affected products

  • Linux Linux Kernel Introduced in c46a6465bac2; fixed in 49891c8fe0cb, 5293a8882c54, 67e1aaf93b49, dcfe4d1f7960

Timeline

  • 2026-04-08: patched: Initial patch authored by Chaitanya Kulkarni
  • 2026-05-28: advisory: CVE-2026-46135 published by NVD

References

Related threats