Executive brief
A vulnerability in the Linux kernel's NVMe driver could cause a system crash when connecting certain high-speed storage devices. This occurs due to an error in how the system manages memory during the initial setup of NVMe drives, particularly those connected via Thunderbolt or unstable PCIe links. An exploit would result in a kernel panic, leading to a complete system outage and potential data loss from unsaved work.
Technical details
A use-after-free vulnerability exists in the nvme-pci driver within the nvme_free_host_mem() function. The root cause is a failure to NULL a pointer (dev->hmb_sgt) after it has been freed via dma_free_noncontiguous(). If an I/O error occurs during Host Memory Buffer (HMB) setup, the error handling path may call nvme_free_host_mem() twice, leading to a double-free or use-after-free scenario. This results in a NULL pointer dereference in iommu_dma_free_noncontiguous() when the kernel attempts to access the stale scatter-gather table. The issue is primarily triggered by PCIe link instability during device probing, particularly on Thunderbolt-attached NVMe devices. Patches have been released for various stable kernel branches to ensure the pointer is cleared after the first free.
Affected products
- Linux Linux kernel 63a5c7a4b4c49ad86c362e9f555e6f343804ee1d to 9525e3a6fbb1d126a22ab2ee86ddea25af581a7c
Timeline
- 2026-04-29: other: Fix authored
- 2026-06-01: patched: Fix committed to stable branches
- 2026-07-19: advisory: NVD publication date