Executive brief
The NVMe Fibre Channel driver in the Linux kernel has a memory leak when initializing I/O requests. If mapping memory for a response buffer fails, previously allocated memory for a command buffer is not properly freed, causing a gradual loss of system memory over time as I/O operations are attempted and fail.
Technical details
The vulnerability is a resource leak in __nvme_fc_init_request() where cmd_iu (command information unit) DMA memory is mapped but not unmapped if a subsequent rsp_iu (response information unit) DMA mapping fails. The code records the error but continues execution, leaving the cmd_iu mapping in place. Because the block-mq layer does not call .exit_request() when .init_request() fails, the leaked memory is never reclaimed. The fix adds an error path that unmaps cmd_iu and properly returns before marking the operation as idle, keeping it in FCPOP_STATE_UNINIT. This affects all Linux kernel versions since the original nvme-fabrics FC transport implementation.
Affected products
- Linux Linux kernel all versions since nvme-fabrics FC support (commit e399441de911)
Timeline
- 2026-09-17: disclosed: Published on NVD
- 2026-09-14: patched: Patch merged into stable kernel tree