« Volver al listado

CVE-2026-23360

Estado: AnalizadaMedia (5.5)—

In the Linux kernel, the following vulnerability has been resolved:

nvme: fix admin queue leak on controller reset

When nvme_alloc_admin_tag_set() is called during a controller reset, a previous admin queue may still exist. Release it properly before allocating a new one to avoid orphaning the old queue.

This fixes a regression introduced by commit 03b3bcd319b3 ("nvme: fix admin request_queue lifetime").

CVSS

Probabilidad de explotación (EPSS)

EPSS (Exploit Prediction Scoring System, de FIRST) estima la probabilidad de que una vulnerabilidad sea explotada en 30 días. Complementa a CVSS (impacto) y a CISA KEV (explotación confirmada).

Tecnologías afectadas (1)

CWE

Referencias

JSON original (NVD)

Mostrar
{
  "id": "CVE-2026-23360",
  "cveTags": [],
  "metrics": {
    "cvssMetricV31": [
      {
        "type": "Primary",
        "source": "nvd@nist.gov",
        "cvssData": {
          "scope": "UNCHANGED",
          "version": "3.1",
          "baseScore": 5.5,
          "attackVector": "LOCAL",
          "baseSeverity": "MEDIUM",
          "vectorString": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H",
          "integrityImpact": "NONE",
          "userInteraction": "NONE",
          "attackComplexity": "LOW",
          "availabilityImpact": "HIGH",
          "privilegesRequired": "LOW",
          "confidentialityImpact": "NONE"
        },
        "impactScore": 3.6,
        "exploitabilityScore": 1.8
      }
    ]
  },
  "affected": [
    {
      "source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
      "affectedData": [
        {
          "repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
          "vendor": "Linux",
          "product": "Linux",
          "versions": [
            {
              "status": "affected",
              "version": "ff037b5f47eeccc1636c03f84cd47db094eb73c9",
              "lessThan": "089a6f17881a82c6c6e05f8564a867be0767eade",
              "versionType": "git"
            },
            {
              "status": "affected",
              "version": "4896491c497226022626c3acc46044fd182f943c",
              "lessThan": "6e28bab900e40e4d610b04f9f82e01983d8fb356",
              "versionType": "git"
            },
            {
              "status": "affected",
              "version": "a505f0ba36ab24176c300d7ff56aff85c2977e6c",
              "lessThan": "2efbc838a26d3da72d8fe05770bdf869d4ca3ac5",
              "versionType": "git"
            },
            {
              "status": "affected",
              "version": "e8061d02b49c5c901980f58d91e96580e9a14acf",
              "lessThan": "64f87b96de0e645a4c066c7cffd753f334446db6",
              "versionType": "git"
            },
            {
              "status": "affected",
              "version": "03b3bcd319b3ab5182bc9aaa0421351572c78ac0",
              "lessThan": "e159eb852aeee95443a9458ecb7d072bbb689913",
              "versionType": "git"
            },
            {
              "status": "affected",
              "version": "03b3bcd319b3ab5182bc9aaa0421351572c78ac0",
              "lessThan": "8eb2b3cdcd9b6631b94b82c1f4f6bc32b40d942f",
              "versionType": "git"
            },
            {
              "status": "affected",
              "version": "03b3bcd319b3ab5182bc9aaa0421351572c78ac0",
              "lessThan": "b84bb7bd913d8ca2f976ee6faf4a174f91c02b8d",
              "versionType": "git"
            },
            {
              "status": "affected",
              "version": "e7dac681790556c131854b97551337aa8042215b",
              "versionType": "git"
            },
            {
              "status": "affected",
              "version": "6.1.167",
              "lessThan": "6.1.168",
              "versionType": "semver"
            },
            {
              "status": "affected",
              "version": "6.6.120",
              "lessThan": "6.6.131",
              "versionType": "semver"
            },
            {
              "status": "affected",
              "version": "6.12.62",
              "lessThan": "6.12.77",
              "versionType": "semver"
            },
            {
              "status": "affected",
              "version": "6.17.12",
              "lessThan": "6.18",
              "versionType": "semver"
            }
          ],
          "programFiles": [
            "drivers/nvme/host/core.c"
          ],
          "defaultStatus": "unaffected"
        },
        {
          "repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
          "vendor": "Linux",
          "product": "Linux",
          "versions": [
            {
              "status": "affected",
              "version": "6.18"
            },
            {
              "status": "unaffected",
              "version": "0",
              "lessThan": "6.18",
              "versionType": "semver"
            },
            {
              "status": "unaffected",
              "version": "6.1.168",
              "versionType": "semver",
              "lessThanOrEqual": "6.1.*"
            },
            {
              "status": "unaffected",
              "version": "6.6.131",
              "versionType": "semver",
              "lessThanOrEqual": "6.6.*"
            },
            {
              "status": "unaffected",
              "version": "6.12.77",
              "versionType": "semver",
              "lessThanOrEqual": "6.12.*"
            },
            {
              "status": "unaffected",
              "version": "6.18.17",
              "versionType": "semver",
              "lessThanOrEqual": "6.18.*"
            },
            {
              "status": "unaffected",
              "version": "6.19.7",
              "versionType": "semver",
              "lessThanOrEqual": "6.19.*"
            },
            {
              "status": "unaffected",
              "version": "7.0",
              "versionType": "original_commit_for_fix",
              "lessThanOrEqual": "*"
            }
          ],
          "programFiles": [
            "drivers/nvme/host/core.c"
          ],
          "defaultStatus": "affected"
        }
      ]
    }
  ],
  "published": "2026-03-25T11:16:34.907",
  "references": [
    {
      "url": "https://git.kernel.org/stable/c/089a6f17881a82c6c6e05f8564a867be0767eade",
      "tags": [
        "Patch"
      ],
      "source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
    },
    {
      "url": "https://git.kernel.org/stable/c/2efbc838a26d3da72d8fe05770bdf869d4ca3ac5",
      "tags": [
        "Patch"
      ],
      "source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
    },
    {
      "url": "https://git.kernel.org/stable/c/64f87b96de0e645a4c066c7cffd753f334446db6",
      "tags": [
        "Patch"
      ],
      "source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
    },
    {
      "url": "https://git.kernel.org/stable/c/6e28bab900e40e4d610b04f9f82e01983d8fb356",
      "tags": [
        "Patch"
      ],
      "source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
    },
    {
      "url": "https://git.kernel.org/stable/c/8eb2b3cdcd9b6631b94b82c1f4f6bc32b40d942f",
      "tags": [
        "Patch"
      ],
      "source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
    },
    {
      "url": "https://git.kernel.org/stable/c/b84bb7bd913d8ca2f976ee6faf4a174f91c02b8d",
      "tags": [
        "Patch"
      ],
      "source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
    },
    {
      "url": "https://git.kernel.org/stable/c/e159eb852aeee95443a9458ecb7d072bbb689913",
      "tags": [
        "Patch"
      ],
      "source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
    }
  ],
  "vulnStatus": "Analyzed",
  "weaknesses": [
    {
      "type": "Primary",
      "source": "nvd@nist.gov",
      "description": [
        {
          "lang": "en",
          "value": "CWE-401"
        }
      ]
    }
  ],
  "descriptions": [
    {
      "lang": "en",
      "value": "In the Linux kernel, the following vulnerability has been resolved:\n\nnvme: fix admin queue leak on controller reset\n\nWhen nvme_alloc_admin_tag_set() is called during a controller reset,\na previous admin queue may still exist. Release it properly before\nallocating a new one to avoid orphaning the old queue.\n\nThis fixes a regression introduced by commit 03b3bcd319b3 (\"nvme: fix\nadmin request_queue lifetime\")."
    },
    {
      "lang": "es",
      "value": "En el kernel de Linux, la siguiente vulnerabilidad ha sido resuelta:\n\nnvme: corrige la fuga de la cola de administración al reiniciar el controlador\n\nCuando se llama a nvme_alloc_admin_tag_set() durante un reinicio del controlador, una cola de administración anterior aún puede existir. Libérela correctamente antes de asignar una nueva para evitar dejar huérfana la cola antigua.\n\nEsto corrige una regresión introducida por el commit 03b3bcd319b3 ('nvme: corrige la vida útil de request_queue de administración')."
    }
  ],
  "lastModified": "2026-06-17T10:21:25.660",
  "configurations": [
    {
      "nodes": [
        {
          "negate": false,
          "cpeMatch": [
            {
              "criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "5A5BC13A-216B-45C3-A63E-D66C3FECFE85",
              "versionEndExcluding": "6.6.131",
              "versionStartIncluding": "6.6.120"
            },
            {
              "criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "F861E4B9-708D-4A3E-9295-278B155F4550",
              "versionEndExcluding": "6.12.77",
              "versionStartIncluding": "6.12.62"
            },
            {
              "criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "1FCE186E-ED64-4D23-A6C7-327D3D61F135",
              "versionEndExcluding": "6.18",
              "versionStartIncluding": "6.17.12"
            },
            {
              "criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "07E9D8CD-82F0-4CC6-8038-BF71758D583C",
              "versionEndExcluding": "6.18.17",
              "versionStartIncluding": "6.18.1"
            },
            {
              "criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "69245D10-0B71-485E-80C3-A64F077004D3",
              "versionEndExcluding": "6.19.7",
              "versionStartIncluding": "6.19"
            },
            {
              "criteria": "cpe:2.3:o:linux:linux_kernel:6.1.167:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "B898A4FB-4E74-40F7-B523-B71FFB681B6D"
            },
            {
              "criteria": "cpe:2.3:o:linux:linux_kernel:6.18:-:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "DCE57113-2223-4308-A0F2-5E6ECFBB3C23"
            },
            {
              "criteria": "cpe:2.3:o:linux:linux_kernel:7.0:rc1:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "F253B622-8837-4245-BCE5-A7BF8FC76A16"
            },
            {
              "criteria": "cpe:2.3:o:linux:linux_kernel:7.0:rc2:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "4AE85AD8-4641-4E7C-A2F4-305E2CD9EE64"
            }
          ],
          "operator": "OR"
        }
      ]
    }
  ],
  "sourceIdentifier": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
}