GPU VulnDB

Database/Kernel, userspace & hypervisor

Linux kernel nvme-fc: error recovery iterates an uninitialized IO tagset when admin connect times out

CVSS 8.8CVE-2026-97409Kernel, userspace & hypervisorcurated

Impact

When an nvme-fc controller in CONNECTING state hits an admin request timeout, ctrl->ioerr_work runs __nvme_fc_abort_outstanding_ios(), which aborts requests in both the admin and IO tagsets. ctrl.queue_count is set early in nvme_fc_alloc_ctrl(), so if fc_ctrl->tag_set was never initialized the code calls blk_mq_tagset_busy_iter() on it anyway - the reported symptom is a lockdep splat during connect failure. The fix checks that the IO tagset was created before iterating busy requests, and cancels ctrl->ioerr_work before removing the IO tagset. The trigger is an FC connectivity loss or a failed admin-queue connect, which is ordinary storage-fabric behaviour rather than something an attacker supplies, so on a GPU node this matters where NVMe-over-FC carries datasets or checkpoints and a fabric flap can destabilize the host. The record shows only the lockdep warning; the surrounding code path touches an uninitialized tagset, so treat the worst case as kernel instability during connect failure rather than as a demonstrated privilege boundary crossing.

Who can reach it

Requires a host using nvme-fc; reached through admin-queue connect timeouts or connectivity loss on the Fibre Channel fabric. No authentication is involved because no login is involved - it is fabric-side conditions, not a user-space entry point. Unprivileged local users cannot reach it.

What to do

Update to a stable kernel with the linked commits and reboot affected hosts; nvme-fc handles boot or dataset storage on these nodes, so a module reload is not a practical substitute. Fold it into the same maintenance window as other FC-NVMe kernel fixes you are carrying. No workaround beyond keeping the FC fabric stable, which is not a security control.

References

Related entries

All Kernel, userspace & hypervisor entries

This entry is curated: imported from vendor advisories with machine assistance, not yet individually verified. Confirm against your vendor's advisory before acting, and report anything wrong.