Database/Kernel, userspace & hypervisor
Linux nvme: sparse NSID gaps make namespace scan iterate billions of times, causing soft lockup
Impact
nvme_scan_ns_list() dropped stale namespaces one NSID at a time across each gap in the reported NSID list, so the loop ran once per NSID in the gap rather than once per namespace actually present. NSIDs are 32-bit, so a target advertising a sparse NSID space makes a single gap spin billions of iterations, producing a soft lockup in nvme_scan_work on the nvme workqueue. This matters most where the NVMe target is not fully trusted or not fully controlled - NVMe-over-Fabrics storage serving GPU nodes - because a target-side NSID layout stalls a CPU on the host and hangs namespace scanning. Impact is availability only; the fix bounds the walk by the namespaces present rather than by the size of the gap.
Who can reach it
A NVMe target (local or over fabrics) that reports a sparse NSID list to the host. No host-side authentication or local access is required, but the attacker must control or influence the target's namespace reporting.
What to do
Take the stable kernel update carrying the nvme_remove_nsid_range() rework (four stable commits referenced). Kernel update and reboot per host; there is no configuration-level mitigation other than not attaching untrusted NVMe targets.
References
Related entries
- Linux kernel (overlayfs, Ubuntu patch): OverlayFS file-capability privilege escalationCVE-2021-3493 · Linux kernel (overlayfs, Ubuntu patch)High
- OpenSSL: X.400 address type confusion in X.509 GeneralNameCVE-2023-0286 · OpenSSLHigh
- Linux kernel (net/sched tcindex): Use-after-free in the tcindex traffic-control filter - local rootCVE-2023-1829 · Linux kernel (net/sched tcindex)High
- QEMU: missing iov bounds check in the virtio-snd input callback gives a guest a heap out-of-bounds writeCVE-2026-3195 · QEMU virtio-snd device (virtio_snd_pcm_in_cb input callback)High
- Linux kernel (arch/x86/kvm/svm): After a CPU offline/online cycle, KVM's ASID generation counter is reset in a way thatCVE-2026-68093 · Linux kernel (arch/x86/kvm/svm)High
- Linux kernel (net/xfrm): A qdisc that reuses skbCVE-2023-53500 · Linux kernel (net/xfrm)High
This entry is curated: imported from vendor advisories with machine assistance, not yet individually verified. Confirm against your vendor's advisory before acting, and report anything wrong.