Database/Kernel, userspace & hypervisor
Linux kernel (drivers/nvme/host): A discard (TRIM) request that is retried and fails again before a fresh payload is
Impact
A discard (TRIM) request that is retried and fails again before a fresh payload is attached frees the same special payload twice, corrupting the kernel heap on a node shared by many tenants. Double-free of a slab object is the classic starting point for privilege escalation, not just a crash.
Who can reach it
Driven by ordinary discard traffic from an unprivileged tenant - fstrim, a filesystem's online discard, or a thin-provisioned volume - so no device passthrough is needed. Turning it into a reliable double free requires the discard to fail and be retried, which is much easier to arrange when the namespace lives on a fabric target rather than a local SSD: the target decides which commands error. Say so plainly - on operator-run local NVMe this is opportunistic, on a tenant-influenced NVMe-oF target it is drivable.
What to do
No fixed version is listed on this record - boot a kernel carrying the linked stable commits. Interim: disable online discard on tenant filesystems (mount without discard, batch with scheduled fstrim on the host) to shrink the exposed path.
References
Related entries
- Linux kernel (drivers/nvme/host): An off-by-one in the Flexible Data Placement index check accepts a placement indexCVE-2026-74361 · Linux kernel (drivers/nvme/host)Critical
- Linux kernel (drivers/nvme/host): The multipath current-path array is sized by the count of possible NUMA nodes butCVE-2026-74384 · Linux kernel (drivers/nvme/host)Critical
- Linux kernel (drivers/nvme/host): The PRP list mempool is sized in the wrong units, so a large I/O that needs two PRPCVE-2022-50756 · Linux kernel (drivers/nvme/host)High
- Linux kernel (drivers/nvme/host): The NVMe/RDMA initiator destroys the queue pair before the connection manager ID, soCVE-2021-47378 · Linux kernel (drivers/nvme/host)Critical
- Linux kernel (drivers/nvme/host): On the NVMe/RDMA initiator, an async-event command can be submitted against an adminCVE-2022-48788 · Linux kernel (drivers/nvme/host)Critical
- Linux kernel (drivers/nvme/host): Same race as the RDMA variant but on NVMe/TCP, which is the far more common fabric inCVE-2022-48789 · Linux kernel (drivers/nvme/host)Critical
This entry is curated: imported from vendor advisories with machine assistance, not yet individually verified. Confirm against your vendor's advisory before acting, and report anything wrong.