HIGH Introduced in 4.5
nvme NsidScan Lockup
CVE-2026-98056
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
KernelScan AI7.5HIGH
01Description
In the Linux kernel, the following vulnerability has been resolved: nvme: remove stale namespaces by NSID range during scan nvme_scan_ns_list() drops the stale namespaces in each gap in the reported NSID list one NSID at a time. Every iteration calls nvme_find_get_ns() to look the namespace up and removes it if it is present. The loop runs once per NSID in the gap rather than once per namespace actually present. NSIDs are 32-bit, so a target with a sparse NSID space can make a single gap spin the loop billions of times with nothing to remove. watchdog: BUG: soft lockup - CPU#4 stuck for 26s! Workqueue: nvme-wq nvme_scan_work [nvme_core] RIP: 0010:__srcu_read_unlock+0xb/0x20 Call Trace: nvme_find_get_ns+0x7d/0xb0 [nvme_core] nvme_scan_ns_list+0xe8/0x280 [nvme_core] nvme_scan_work+0x18a/0x280 [nvme_core] process_one_work+0x197/0x380 worker_thread+0x2fe/0x410 kthread+0xe0/0x100 Rename nvme_remove_invalid_namespaces() to nvme_remove_nsid_range() and give it an open (start, end) NSID range. ctrl->namespaces is sorted by NSID, so the whole gap is dropped in a single walk that stops once end is reached. This bounds the work by the namespaces that are present instead of by the size of the gap.
02KernelScan AI Analysis
Risk summary
Systems with NVMe storage (PCIe or NVMe-oF) are vulnerable to a denial-of-service via soft lockup when a malicious or misconfigured NVMe controller reports a sparse namespace identifier list during the automatic namespace scan. The scan loop iterates over every possible 32-bit namespace identifier in each gap, potentially spinning for tens of seconds and hanging a CPU core. Both locally connected PCIe NVMe devices and network-attached NVMe-oF targets can trigger this condition.
Vulnerability analysis
The NVMe namespace scanning routine removes stale namespaces by iterating over every possible namespace identifier in each gap between reported entries, calling a lookup function once per identifier. Because identifiers are 32-bit, a malicious NVMe controller can present a sparse namespace list that forces billions of empty lookup iterations, hanging a CPU core for tens of seconds and causing a soft lockup. The fix replaces the per-identifier loop with a single walk over the controller's sorted namespace list bounded by a start and end range, so the work scales with the number of namespaces present rather than the gap size. A malicious NVMe device connected over PCIe or an NVMe-oF target reachable over the network can trigger this by reporting a sparse identifier list during the automatic namespace scan.
Lifecycle
03Fix Versions
| Branch | Introduced | Fixed in | Patch commit |
|---|---|---|---|
| 6.12 | 4.5 | 6.12.111 | c84ad7407fb1 |
| 6.18 | 4.5 | 6.18.53 | f56b2bb4b18b |
| 7.2 | 4.5 | 7.2.7 | 52200fc41a79 |
| mainline | 4.5 | 7.3-rc2 | 4ed7f3d7d435 |