KernelScan.io

HIGH Introduced in 4.5

nvme NsidScan Lockup

CVE-2026-98056

CVSS 7.5 / 10.0 NVD

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H

KernelScan AI7.5HIGH

01

In the Linux kernel, the following vulnerability has been resolved: nvme: remove stale namespaces by NSID range during scan nvme_scan_ns_list() drops the stale namespaces in each gap in the reported NSID list one NSID at a time. Every iteration calls nvme_find_get_ns() to look the namespace up and removes it if it is present. The loop runs once per NSID in the gap rather than once per namespace actually present. NSIDs are 32-bit, so a target with a sparse NSID space can make a single gap spin the loop billions of times with nothing to remove. watchdog: BUG: soft lockup - CPU#4 stuck for 26s! Workqueue: nvme-wq nvme_scan_work [nvme_core] RIP: 0010:__srcu_read_unlock+0xb/0x20 Call Trace: nvme_find_get_ns+0x7d/0xb0 [nvme_core] nvme_scan_ns_list+0xe8/0x280 [nvme_core] nvme_scan_work+0x18a/0x280 [nvme_core] process_one_work+0x197/0x380 worker_thread+0x2fe/0x410 kthread+0xe0/0x100 Rename nvme_remove_invalid_namespaces() to nvme_remove_nsid_range() and give it an open (start, end) NSID range. ctrl->namespaces is sorted by NSID, so the whole gap is dropped in a single walk that stops once end is reached. This bounds the work by the namespaces that are present instead of by the size of the gap.

02

Engine v0.6.0

Risk summary

Systems with NVMe storage (PCIe or NVMe-oF) are vulnerable to a denial-of-service via soft lockup when a malicious or misconfigured NVMe controller reports a sparse namespace identifier list during the automatic namespace scan. The scan loop iterates over every possible 32-bit namespace identifier in each gap, potentially spinning for tens of seconds and hanging a CPU core. Both locally connected PCIe NVMe devices and network-attached NVMe-oF targets can trigger this condition.

Affecteddrivers/nvme/host/core.c (nvme core)

Vulnerability analysis

The NVMe namespace scanning routine removes stale namespaces by iterating over every possible namespace identifier in each gap between reported entries, calling a lookup function once per identifier. Because identifiers are 32-bit, a malicious NVMe controller can present a sparse namespace list that forces billions of empty lookup iterations, hanging a CPU core for tens of seconds and causing a soft lockup. The fix replaces the per-identifier loop with a single walk over the controller's sorted namespace list bounded by a start and end range, so the work scales with the number of namespaces present rather than the gap size. A malicious NVMe device connected over PCIe or an NVMe-oF target reachable over the network can trigger this by reporting a sparse identifier list during the automatic namespace scan.

03

BranchIntroducedFixed inPatch commit
6.124.56.12.111c84ad7407fb1
6.184.56.18.53f56b2bb4b18b
7.24.57.2.752200fc41a79
mainline4.57.3-rc24ed7f3d7d435