CRITICAL Introduced in 4.15
nvme Namespace UAF
CVE-2026-89972
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
KernelScan AI6.2MEDIUM
01Description
In the Linux kernel, the following vulnerability has been resolved: nvme: add missing SRCU grace period in error path nvme_alloc_ns() error path at out_unlink_ns removes ns from the namespace head siblings list with list_del_rcu(&ns->siblings) but does not wait for SRCU readers before freeing the namespace struct. Multipath code iterates the head->list under srcu_read_lock() in nvme_find_path() and nvme_mpath_revalidate_paths(), so a concurrent reader can still hold a reference to ns when kfree(ns) runs. The normal removal path in nvme_ns_remove() correctly calls synchronize_srcu(&ns->head->srcu) after list_del_rcu() to wait for in-progress readers. Add the same grace period in the error path.
02KernelScan AI Analysis
Risk summary
Systems using NVMe multipath are at risk of a use-after-free in the namespace allocation error path. An administrator who can trigger namespace scanning or allocation failures on an NVMe controller could exploit a race with concurrent multipath I/O to corrupt kernel memory, potentially leading to privilege escalation or a system crash.
Vulnerability analysis
When NVMe namespace allocation fails partway through, the error path removes the namespace from the multipath siblings list but frees the namespace structure without waiting for SRCU readers to finish. Concurrent multipath path-selection code that iterates the same list under SRCU protection can still be holding a pointer to the namespace at the moment it is freed, resulting in a use-after-free. The fix adds the same SRCU grace-period synchronization that the normal namespace removal path already performs, ensuring all in-progress readers have released their SRCU locks before the structure is freed. This is reachable on local systems with NVMe multipath configured and requires administrative privileges to trigger the namespace allocation or re-scan operation that enters the error path.
Lifecycle
03Fix Versions
| Branch | Introduced | Fixed in | Patch commit |
|---|---|---|---|
| 6.18 | 4.15 | 6.18.51 | d663944dbad8 |
| 7.2 | 4.15 | 7.2.5 | 76023560d60f |
| mainline | 4.15 | 7.3-rc2 | ef248d5de446 |