Executive brief
The Linux kernel's NVMe target (nvmet) module has a memory reference leak in its submission queue creation routine. When validation fails during queue setup, the code fails to release a kernel object reference, causing a gradual accumulation of orphaned kernel memory. This can lead to kernel memory exhaustion and denial of service on systems running vulnerable kernels.
Technical details
The vulnerability is a refcount leak in the nvmet_sq_create() function within the NVMe target subsystem (drivers/nvme/target/core.c). A reference on the controller (ctrl) is acquired via kref_get_unless_zero() before calling nvmet_check_sqid(). If nvmet_check_sqid() returns a non-success status, the function returns the error code directly without releasing the acquired reference, causing a leak. The fix redirects the error path to jump to an existing "ctrl_put" label that properly invokes nvmet_ctrl_put(ctrl). The vulnerability requires no authentication or network access—only the ability to issue invalid submission queue creation requests on systems with nvmet exposed.
Affected products
- Linux Linux Kernel Affected versions prior to fix commit 34b9a83c50660148bde01cde16451dbe78369749
Timeline
- 2026-08-15: disclosed
- 2026-06-09: patched: Upstream fix commit 34b9a83c50660148bde01cde16451dbe78369749