Junglewise Threat Intelligence

CVE-2026-72128: Linux kernel nvmet refcount leak in nvmet_sq_create()

CVE-2026-72128 · Severity: info · Published 2026-08-15

Technologies: Linux Kernel. Vendors: Linux.

Executive brief

The Linux kernel's NVMe target (nvmet) module has a memory reference leak in its submission queue creation routine. When validation fails during queue setup, the code fails to release a kernel object reference, causing a gradual accumulation of orphaned kernel memory. This can lead to kernel memory exhaustion and denial of service on systems running vulnerable kernels.

Technical details

The vulnerability is a refcount leak in the nvmet_sq_create() function within the NVMe target subsystem (drivers/nvme/target/core.c). A reference on the controller (ctrl) is acquired via kref_get_unless_zero() before calling nvmet_check_sqid(). If nvmet_check_sqid() returns a non-success status, the function returns the error code directly without releasing the acquired reference, causing a leak. The fix redirects the error path to jump to an existing "ctrl_put" label that properly invokes nvmet_ctrl_put(ctrl). The vulnerability requires no authentication or network access—only the ability to issue invalid submission queue creation requests on systems with nvmet exposed.

Affected products

  • Linux Linux Kernel Affected versions prior to fix commit 34b9a83c50660148bde01cde16451dbe78369749

Timeline

  • 2026-08-15: disclosed
  • 2026-06-09: patched: Upstream fix commit 34b9a83c50660148bde01cde16451dbe78369749

References

Related threats