nvmet-tcp: fix race between ICReq handling and queue teardown
To determine the support lifecycle for your software, see the Microsoft Support Lifecycle: https://support.microsoft.com/lifecycle
AI Analysis
Technical Summary
The vulnerability in the Linux kernel's nvmet-tcp module involves a race condition between handling Initialization Connection Requests (ICReq) and the teardown of the target-side queue. Specifically, nvmet_tcp_handle_icreq() updates the queue state without proper serialization against queue teardown, allowing the queue state to be overwritten after it has been marked as disconnecting. This can lead to a second reference release on an already released queue, causing memory corruption or kernel crashes. The flaw also affects the ICResp send failure path, where a send error can reopen the teardown window. The fix involves serializing state transitions with a lock and aborting state changes if teardown has started, using an internal sentinel error code to manage the process.
Potential Impact
Successful exploitation can cause kernel memory corruption or crashes due to double release of queue references, leading to denial of service or potential system instability. The vulnerability affects the NVMe/TCP target implementation in the Linux kernel, impacting systems that use this feature for storage networking.
Mitigation Recommendations
Patch status is not yet confirmed — check the vendor advisory for current remediation guidance. Until an official fix is available, users should monitor vendor communications for updates. The vendor advisory does not indicate that no action is required or that the issue is already mitigated.
nvmet-tcp: fix race between ICReq handling and queue teardown
Description
To determine the support lifecycle for your software, see the Microsoft Support Lifecycle: https://support.microsoft.com/lifecycle
CVSS v3.1
Score 9.8critical
Affected software
Weaknesses
AI-Powered Analysis
Machine-generated threat intelligence
Technical Analysis
The vulnerability in the Linux kernel's nvmet-tcp module involves a race condition between handling Initialization Connection Requests (ICReq) and the teardown of the target-side queue. Specifically, nvmet_tcp_handle_icreq() updates the queue state without proper serialization against queue teardown, allowing the queue state to be overwritten after it has been marked as disconnecting. This can lead to a second reference release on an already released queue, causing memory corruption or kernel crashes. The flaw also affects the ICResp send failure path, where a send error can reopen the teardown window. The fix involves serializing state transitions with a lock and aborting state changes if teardown has started, using an internal sentinel error code to manage the process.
Potential Impact
Successful exploitation can cause kernel memory corruption or crashes due to double release of queue references, leading to denial of service or potential system instability. The vulnerability affects the NVMe/TCP target implementation in the Linux kernel, impacting systems that use this feature for storage networking.
Mitigation Recommendations
Patch status is not yet confirmed — check the vendor advisory for current remediation guidance. Until an official fix is available, users should monitor vendor communications for updates. The vendor advisory does not indicate that no action is required or that the issue is already mitigated.
Technical Details
- Gcve Source
- db.gcve.eu
- Csaf Category
- csaf_vex
- Csaf Version
- 2.0
- Publisher
- Microsoft Security Response Center
- Advisory Id
- msrc_CVE-2026-46135
- Cve Count
- 1
- Additional Cves
- []
- Cvss Version
- 3.1
Threat ID: 6a19fec3e29bf47b500fe073
Added to database: 05/29/2026, 21:01:55 UTC
Last enriched: 07/04/2026, 23:23:35 UTC
Last updated: 07/31/2026, 19:22:59 UTC
Views: 57
Community Reviews
0 reviewsCrowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.
Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.
Actions
Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.
Need more coverage?
Upgrade to Pro Console for AI refresh and higher limits.
For incident response and remediation, OffSeq services can help resolve threats faster.
Latest Threats
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.