Database/Kernel, userspace & hypervisor
Linux kernel NVMe target core (controller teardown racing queue-pair establishment): An initiator that disconnects
Impact
An initiator that disconnects while its admin CONNECT is still in flight opens a window where nvmet_sq_destroy() runs concurrently with controller allocation, leaking the controller and its pending async event requests. A remote party controls both halves - connect, then abandon - so the leak is repeatable on demand until the target exhausts memory. Connect-and-drop is also indistinguishable from an unstable client, so it is quiet.
Who can reach it
Remote, unauthenticated. Repeated connect/abort cycles against the target.
What to do
Kernel update fixing the ordering in nvmet_sq_destroy(). Watch target memory and connection-churn metrics as a detection proxy; allow-list initiators to limit who can churn.
References
Related entries
- Linux kernel NVMe-oF TCP target (nvmet-tcp queue command allocation failure): When command allocation for a new queueCVE-2024-46737 · Linux kernel NVMe-oF TCP target (nvmet-tcp queue command allocation failure)High
- Linux kernel SMC (CLC message drain loop, unchecked sock_recvmsg return): The length field in the CLC header isCVE-2024-57791 · Linux kernel SMC (CLC message drain loop, unchecked sock_recvmsg return)High
- QEMU (NBD server): Improper synchronisation during socket closure - DoS of the QEMU NBD serverCVE-2024-7409 · QEMU (NBD server)High
- QEMU: use-after-free in the VNC WebSocket handshake crashes the VM process before client authenticationCVE-2025-11234 · QEMU QIOChannelWebsock (VNC WebSocket handshake)High
- Linux kernel (net/tls): If a page allocation fails while the TLS strparser is copying a partial record, the receiveCVE-2025-38018 · Linux kernel (net/tls)High
- Linux kernel (drivers/nvme/target): A connecting client that abandons the TCP connection at the right moment duringCVE-2025-38035 · Linux kernel (drivers/nvme/target)High
This entry is curated: imported from vendor advisories with machine assistance, not yet individually verified. Confirm against your vendor's advisory before acting, and report anything wrong.