GPU VulnDB

Database/Kernel, userspace & hypervisor

Linux kernel nvmet-rdma: queue and IB resources leak when the connect backlog is exceeded

CVSS 5.5CVE-2026-98152Kernel, userspace & hypervisorcurated

Impact

When the number of pending disconnecting queues exceeds the backlog limit, the nvmet-rdma connect path drops only the device reference and leaks the queue it just allocated along with its InfiniBand resources. Each rejected connect therefore costs the target kernel memory and HCA resources that are never returned, so a host that reconnects aggressively - or simply flapping initiators on the fabric - can grind a storage target down to allocation failures. On a GPU fleet this is the node exporting NVMe-oF over RDMA to training jobs, so the damage is felt as fabric-wide storage stalls rather than a single tenant's problem, and recovery means rebooting the box that every job is reading from. Only nodes actually running the nvmet-rdma target are exposed; initiator-only and headless compute nodes are not.

Who can reach it

Local or fabric-adjacent: anyone able to open NVMe-oF/RDMA connections to the target - typically any host on the storage fabric that is permitted to connect - can drive the leak by repeatedly connecting and disconnecting. No authentication beyond whatever the NVMe-oF subsystem's host allowlist enforces.

What to do

Update to a stable kernel carrying the nvmet-rdma connect-path fix on every node that runs the NVMe-oF RDMA target, then drain and reboot it; the nvmet module cannot be meaningfully reloaded while subsystems are exported. Interim mitigation is to tighten which hosts may connect to the target and to watch for growing slab usage on the target. No distribution-fixed version is given in the record, only the stable git commits.

References

Related entries

All Kernel, userspace & hypervisor entries

This entry is curated: imported from vendor advisories with machine assistance, not yet individually verified. Confirm against your vendor's advisory before acting, and report anything wrong.