Database/Kernel, userspace & hypervisor
Linux kernel nvme-fc: error recovery iterates an uninitialized IO tagset when admin connect times out
Impact
When an nvme-fc controller in CONNECTING state hits an admin request timeout, ctrl->ioerr_work runs __nvme_fc_abort_outstanding_ios(), which aborts requests in both the admin and IO tagsets. ctrl.queue_count is set early in nvme_fc_alloc_ctrl(), so if fc_ctrl->tag_set was never initialized the code calls blk_mq_tagset_busy_iter() on it anyway - the reported symptom is a lockdep splat during connect failure. The fix checks that the IO tagset was created before iterating busy requests, and cancels ctrl->ioerr_work before removing the IO tagset. The trigger is an FC connectivity loss or a failed admin-queue connect, which is ordinary storage-fabric behaviour rather than something an attacker supplies, so on a GPU node this matters where NVMe-over-FC carries datasets or checkpoints and a fabric flap can destabilize the host. The record shows only the lockdep warning; the surrounding code path touches an uninitialized tagset, so treat the worst case as kernel instability during connect failure rather than as a demonstrated privilege boundary crossing.
Who can reach it
Requires a host using nvme-fc; reached through admin-queue connect timeouts or connectivity loss on the Fibre Channel fabric. No authentication is involved because no login is involved - it is fabric-side conditions, not a user-space entry point. Unprivileged local users cannot reach it.
What to do
Update to a stable kernel with the linked commits and reboot affected hosts; nvme-fc handles boot or dataset storage on these nodes, so a module reload is not a practical substitute. Fold it into the same maintenance window as other FC-NVMe kernel fixes you are carrying. No workaround beyond keeping the FC fabric stable, which is not a security control.
References
Related entries
- Linux kernel qla2xxx: unserialized NVMe-FC unsolicited-context list can be corrupted by concurrent add and deleteCVE-2026-97527 · Linux kernel scsi qla2xxx (fcport->unsol_ctx_head list unserialized across ISR, DPC and NVMe-FC callbacks)High
- Linux kernel qla2xxx: NVMe-FC unsolicited context freed while still linked, leaving a freed node on the listCVE-2026-97528 · Linux kernel scsi qla2xxx (uctx freed without list_del() on qla_nvme_xmt_ls_rsp() error path)High
- Linux kernel mlx5_core representor TC path + net/sched tc extension: The TC_SKB_EXT skb extension is not zeroedCVE-2021-47136 · Linux kernel mlx5_core representor TC path + net/sched tc extensionHigh
- Linux kernel (net/tls): When a BPF socket policy shrinks the plaintext after the ciphertext length was computed, kTLSCVE-2025-38608 · Linux kernel (net/tls)High
- Linux kernel libceph: truncated monitor reply decodes stale bytes from the reused bufferCVE-2026-68433 · Linux kernel libceph (MON_GET_VERSION_REPLY decode bound)High
- sudo: intercept policy checks skipped for execveat, letting allowed users run denied commandsCVE-2026-82474 · sudo (ptrace-based intercept mode, execveat/fexecve path)High
This entry is curated: imported from vendor advisories with machine assistance, not yet individually verified. Confirm against your vendor's advisory before acting, and report anything wrong.