VDB
GHSA-mx2c-4m76-c7r4
GHSA-mx2c-4m76-c7r4
PUBLISHED
CVSS 5.5 MEDIUM
In the Linux kernel, the following vulnerability has been resolved: nvme: fix admin queue leak on controller reset When nvme_alloc_admin_tag_set() is called during a controller reset, a previous admin queue may still exist. Release it properly before allocating a new one to avoid orphaning the old queue. This fixes a regression introduced by commit 03b3bcd319b3 ("nvme: fix admin request_queue lifetime").
Risk Scores
CVSS v3.1
5.5
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
Timeline
- Mar 25, 2026 CVE Published
- Apr 10, 2026 Security Advisory
- Apr 24, 2026 CVE Updated
References
- https://nvd.nist.gov/vuln/detail/CVE-2026-23360 advisory
- https://git.kernel.org/stable/c/089a6f17881a82c6c6e05f8564a867be0767eade url
- https://git.kernel.org/stable/c/2efbc838a26d3da72d8fe05770bdf869d4ca3ac5 url
- https://git.kernel.org/stable/c/64f87b96de0e645a4c066c7cffd753f334446db6 url
- https://git.kernel.org/stable/c/6e28bab900e40e4d610b04f9f82e01983d8fb356 url
- https://git.kernel.org/stable/c/8eb2b3cdcd9b6631b94b82c1f4f6bc32b40d942f url
- https://git.kernel.org/stable/c/b84bb7bd913d8ca2f976ee6faf4a174f91c02b8d url
- https://git.kernel.org/stable/c/e159eb852aeee95443a9458ecb7d072bbb689913 url