Database/Kernel, userspace & hypervisor
Linux kernel (drivers/nvme/target): Every connection that dies partway through queue allocation on the NVMe-oF TCP
Impact
Every connection that dies partway through queue allocation on the NVMe-oF TCP target leaks a page-fragment cache reference that is never reclaimed. An unauthenticated peer that loops connect-then-drop drives unbounded kernel memory growth on the storage node until it OOMs, which is a full outage for every tenant using that target.
Who can reach it
Any peer with network reach to the nvmet-tcp listening port. The leak happens in nvmet_tcp_alloc_queue's error path, before the connection is authenticated or associated with a subsystem, so no credentials and no tenant device node are needed - just repeated half-open connections. Requires the node to be running nvmet with a TCP port enabled.
What to do
No fixed version is listed on this record - boot a kernel carrying the linked stable commits. Interim: restrict who can reach the nvmet-tcp port (storage VLAN only), rate-limit new connections to it at the firewall, and monitor slab growth on target nodes.
References
Related entries
- Linux kernel (drivers/nvme/target): A client that asks the target to create a submission queue with an invalid queue IDCVE-2026-72128 · Linux kernel (drivers/nvme/target)Medium
- Linux kernel (drivers/nvme/target): The target disables a namespace without waiting for in-flight I/O to drain, so aCVE-2025-21850 · Linux kernel (drivers/nvme/target)Critical
- Linux kernel (drivers/nvme/target): A client connected to your NVMe-oF TCP target can drive a reference-count underflowCVE-2026-64534 · Linux kernel (drivers/nvme/target)Critical
- Linux kernel (drivers/nvme/target): When the target's peer-to-peer memory pool runs dry, it still tries to return theCVE-2021-47130 · Linux kernel (drivers/nvme/target)High
- Linux kernel (drivers/nvme/target): A connecting client that abandons the TCP connection at the right moment duringCVE-2025-38035 · Linux kernel (drivers/nvme/target)High
- Linux kernel (drivers/nvme/target): Every command a client sends to the target carrying metadata (protectionCVE-2025-38405 · Linux kernel (drivers/nvme/target)High
This entry is curated: imported from vendor advisories with machine assistance, not yet individually verified. Confirm against your vendor's advisory before acting, and report anything wrong.