Bug 2536768 (CVE-2026-90233) - CVE-2026-90233 kernel: nvme-pci: release descriptor pools on probe failure
Summary: CVE-2026-90233 kernel: nvme-pci: release descriptor pools on probe failure
Keywords:
Status: NEW
Alias: CVE-2026-90233
Product: Security Response
Classification: Other
Component: vulnerability
Version: unspecified
Hardware: All
OS: Linux
low
low
Target Milestone: ---
Assignee: Product Security DevOps Team
QA Contact:
URL:
Whiteboard:
Depends On:
Blocks:
TreeView+ depends on / blocked
 
Reported: 2026-09-17 19:30 UTC by OSIDB Bzimport
Modified: 2026-10-05 13:35 UTC (History)
17 users (show)

Fixed In Version:
Clone Of:
Environment:
Last Closed:
Embargoed:


Attachments (Terms of Use)

Description OSIDB Bzimport 2026-09-17 19:30:12 UTC
In the Linux kernel, the following vulnerability has been resolved:

nvme-pci: release descriptor pools on probe failure

The per-NUMA-node descriptor DMA pools are created lazily from
nvme_init_hctx_common() once the admin tag set is allocated, but they are
only destroyed in nvme_remove() via nvme_release_descriptor_pools(). Any
probe failure after the admin tag set has been allocated unwinds through
the out_disable label and nvme_pci_free_ctrl(), neither of which releases
the pools, leaking the dma_pool objects.

Release the descriptor pools in the out_disable error path. It must not
be added to nvme_pci_free_ctrl(), as that would double-free against
nvme_remove() on the normal teardown path.


Note You need to log in before you can comment on or make changes to this bug.