Database/Kernel, userspace & hypervisor
Linux kernel (drivers/nvme/target): Ordinary client I/O to an nvmet block-device namespace can hit a completion race
Impact
Ordinary client I/O to an nvmet block-device namespace can hit a completion race where the target's inline bio is torn down while the same bio is being re-submitted, dereferencing a NULL cgroup pointer in the block layer. The shared storage node crashes on the normal read/write path, so a single tenant's I/O pattern can knock out the target for all of them.
Who can reach it
Driven by a connected NVMe-oF client's regular I/O against an exported namespace backed by a block device - no special opcode and no privilege on the target side. Any tenant or peer that has been allowed to connect to the subsystem can push the target into the window; it is a timing race, so it favours high-rate I/O rather than a crafted packet. Requires nvmet configured with a bdev-backed namespace.
What to do
Update to 6.12.69 / 6.16 or later. Interim: no clean workaround short of stopping the nvmet subsystem export or moving affected namespaces to a patched node - the path is the normal I/O path, so it cannot be gated by configuration.
References
Related entries
- Linux kernel (drivers/nvme/target): A client that completes the TLS handshake against the NVMe-oF TCP target and thenCVE-2026-74385 · Linux kernel (drivers/nvme/target)High
- Linux kernel (drivers/nvme/target): Every connection that dies partway through queue allocation on the NVMe-oF TCPCVE-2026-74386 · Linux kernel (drivers/nvme/target)High
- Linux kernel (drivers/nvme/target): A client that asks the target to create a submission queue with an invalid queue IDCVE-2026-72128 · Linux kernel (drivers/nvme/target)Medium
- Linux kernel (drivers/nvme/target): The target disables a namespace without waiting for in-flight I/O to drain, so aCVE-2025-21850 · Linux kernel (drivers/nvme/target)Critical
- Linux kernel (drivers/nvme/target): A client connected to your NVMe-oF TCP target can drive a reference-count underflowCVE-2026-64534 · Linux kernel (drivers/nvme/target)Critical
- Linux kernel (drivers/nvme/target): When the target's peer-to-peer memory pool runs dry, it still tries to return theCVE-2021-47130 · Linux kernel (drivers/nvme/target)High
This entry is curated: imported from vendor advisories with machine assistance, not yet individually verified. Confirm against your vendor's advisory before acting, and report anything wrong.