CVE-2026-64321 PUBLISHED

nvme: target: rdma: fix ndev refcount leak on queue connect

Assigner: Linux
Reserved: 19.07.2026 Published: 25.07.2026 Updated: 25.07.2026

In the Linux kernel, the following vulnerability has been resolved:

nvme: target: rdma: fix ndev refcount leak on queue connect

nvmet_rdma_queue_connect() calls nvmet_rdma_find_get_device() which acquires a reference on the returned ndev via kref_get(). On the path where the host queue backlog is exceeded and the function returns NVME_SC_CONNECT_CTRL_BUSY, reference of ndev is not released, leaking the kref.

Fix this by adding a goto to the existing put_device label before the early return.

Product Status

Vendor Linux
Product Linux
Versions Default: unaffected
  • affected from 31deaeb11ba7a885116c9c30892b9f763c04d59c to d65fe42820b890a6a4644de0a95a812471f79ad3 (excl.)
  • affected from 31deaeb11ba7a885116c9c30892b9f763c04d59c to a8803c4f0ac3fa7df5551bbb5a8800c434a94357 (excl.)
  • affected from 31deaeb11ba7a885116c9c30892b9f763c04d59c to 5828517d17eda27f21d29ea14800c9e0a57bad11 (excl.)
  • affected from 31deaeb11ba7a885116c9c30892b9f763c04d59c to badc53620fe813b3a9f727ef9526f98567c2c898 (excl.)
Vendor Linux
Product Linux
Versions Default: affected
  • Version 6.8 is affected
  • unaffected from 0 to 6.8 (excl.)
  • unaffected from 6.12.96 to 6.12.* (incl.)
  • unaffected from 6.18.39 to 6.18.* (incl.)
  • unaffected from 7.1.4 to 7.1.* (incl.)
  • unaffected from 7.2-rc1 to * (incl.)

References