KernelScan.io

CRITICAL Introduced in 6.0

nvmet AuthTimeout UAF

CVE-2026-89970

CVSS 9.8 / 10.0 NVD

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

KernelScan AI8.1HIGH

01

In the Linux kernel, the following vulnerability has been resolved: nvmet-auth: Synchronize timeout work during SQ teardown nvmet_auth_sq_free() cancels auth_expired_work with cancel_delayed_work(). If the work has already started, cancellation does not wait for the callback. Transport teardown can consequently free or reuse the queue containing struct nvmet_sq while nvmet_auth_expired_work() still accesses that SQ. Add a teardown-specific helper that synchronously drains the delayed work before freeing authentication state, and use it from nvmet_sq_destroy(). Keep the non-synchronous helper for in-band authentication state cleanup, where the SQ owner remains alive.

02

Engine v0.6.0

Risk summary

A remote attacker connecting as an NVMe-oF initiator can trigger a use-after-free in the kernel's NVMe target authentication timeout handling. By initiating authentication and timing the session expiry with connection teardown, the attacker can exploit a race window where the timeout work callback accesses freed queue memory. This can lead to kernel memory corruption, potentially resulting in code execution or a system crash on any system running an NVMe-oF target exposed to the network.

Affecteddrivers/nvme/target/auth.c (nvmet-auth)

Vulnerability analysis

When an NVMe-oF authentication session times out, a delayed work callback is scheduled to clean up the authentication state. During normal queue teardown, the code cancelled this work using a non-synchronous cancel that does not wait if the callback has already started executing. This created a window where the teardown path could free the submission queue and its authentication state while the timeout callback was still running and accessing that same memory, resulting in a use-after-free. The fix introduces a teardown-specific helper that synchronously drains the delayed work—waiting for any in-flight callback to complete—before freeing authentication state, and uses it during queue destruction. The original non-synchronous helper is retained for in-band cleanup paths where the queue owner is guaranteed to remain alive. The vulnerability is reachable by any remote NVMe-oF initiator that can connect to a target configured with authentication enabled; no special privileges are required beyond network access to the NVMe target port.

03

BranchIntroducedFixed inPatch commit
6.16.06.1.188664022fa1c93
6.66.06.6.157c3c126a6142a
6.126.06.12.110c17c87bde6d6
6.186.06.18.517555ddd60af7
mainline6.07.3-rc2eaa948c0e19b
7.26.07.2.5eb4f9127a2b8