CRITICAL Introduced in 6.0
nvmet AuthTimeout UAF
CVE-2026-89970
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
KernelScan AI8.1HIGH
01Description
In the Linux kernel, the following vulnerability has been resolved: nvmet-auth: Synchronize timeout work during SQ teardown nvmet_auth_sq_free() cancels auth_expired_work with cancel_delayed_work(). If the work has already started, cancellation does not wait for the callback. Transport teardown can consequently free or reuse the queue containing struct nvmet_sq while nvmet_auth_expired_work() still accesses that SQ. Add a teardown-specific helper that synchronously drains the delayed work before freeing authentication state, and use it from nvmet_sq_destroy(). Keep the non-synchronous helper for in-band authentication state cleanup, where the SQ owner remains alive.
02KernelScan AI Analysis
Risk summary
A remote attacker connecting as an NVMe-oF initiator can trigger a use-after-free in the kernel's NVMe target authentication timeout handling. By initiating authentication and timing the session expiry with connection teardown, the attacker can exploit a race window where the timeout work callback accesses freed queue memory. This can lead to kernel memory corruption, potentially resulting in code execution or a system crash on any system running an NVMe-oF target exposed to the network.
Vulnerability analysis
When an NVMe-oF authentication session times out, a delayed work callback is scheduled to clean up the authentication state. During normal queue teardown, the code cancelled this work using a non-synchronous cancel that does not wait if the callback has already started executing. This created a window where the teardown path could free the submission queue and its authentication state while the timeout callback was still running and accessing that same memory, resulting in a use-after-free. The fix introduces a teardown-specific helper that synchronously drains the delayed work—waiting for any in-flight callback to complete—before freeing authentication state, and uses it during queue destruction. The original non-synchronous helper is retained for in-band cleanup paths where the queue owner is guaranteed to remain alive. The vulnerability is reachable by any remote NVMe-oF initiator that can connect to a target configured with authentication enabled; no special privileges are required beyond network access to the NVMe target port.
Lifecycle
03Fix Versions
| Branch | Introduced | Fixed in | Patch commit |
|---|---|---|---|
| 6.1 | 6.0 | 6.1.188 | 664022fa1c93 |
| 6.6 | 6.0 | 6.6.157 | c3c126a6142a |
| 6.12 | 6.0 | 6.12.110 | c17c87bde6d6 |
| 6.18 | 6.0 | 6.18.51 | 7555ddd60af7 |
| mainline | 6.0 | 7.3-rc2 | eaa948c0e19b |
| 7.2 | 6.0 | 7.2.5 | eb4f9127a2b8 |