CVE-2026-23360 PUBLISHED

nvme: fix admin queue leak on controller reset

Assigner: Linux
Reserved: 13.01.2026 Published: 25.03.2026 Updated: 25.03.2026

In the Linux kernel, the following vulnerability has been resolved:

nvme: fix admin queue leak on controller reset

When nvme_alloc_admin_tag_set() is called during a controller reset, a previous admin queue may still exist. Release it properly before allocating a new one to avoid orphaning the old queue.

This fixes a regression introduced by commit 03b3bcd319b3 ("nvme: fix admin request_queue lifetime").

Product Status

Vendor Linux
Product Linux
Versions Default: unaffected
  • affected from e8061d02b49c5c901980f58d91e96580e9a14acf to 64f87b96de0e645a4c066c7cffd753f334446db6 (excl.)
  • affected from 03b3bcd319b3ab5182bc9aaa0421351572c78ac0 to e159eb852aeee95443a9458ecb7d072bbb689913 (excl.)
  • affected from 03b3bcd319b3ab5182bc9aaa0421351572c78ac0 to 8eb2b3cdcd9b6631b94b82c1f4f6bc32b40d942f (excl.)
  • affected from 03b3bcd319b3ab5182bc9aaa0421351572c78ac0 to b84bb7bd913d8ca2f976ee6faf4a174f91c02b8d (excl.)
  • Version ff037b5f47eeccc1636c03f84cd47db094eb73c9 is affected
  • Version a505f0ba36ab24176c300d7ff56aff85c2977e6c is affected
  • Version e7dac681790556c131854b97551337aa8042215b is affected
Vendor Linux
Product Linux
Versions Default: affected
  • Version 6.18 is affected
  • unaffected from 0 to 6.18 (excl.)
  • unaffected from 6.12.77 to 6.12.* (incl.)
  • unaffected from 6.18.17 to 6.18.* (incl.)
  • unaffected from 6.19.7 to 6.19.* (incl.)
  • unaffected from 7.0-rc3 to * (incl.)

References