CVE-2026-23360
Estado: AnalizadaMedia (5.5)—
In the Linux kernel, the following vulnerability has been resolved:
nvme: fix admin queue leak on controller reset
When nvme_alloc_admin_tag_set() is called during a controller reset, a previous admin queue may still exist. Release it properly before allocating a new one to avoid orphaning the old queue.
This fixes a regression introduced by commit 03b3bcd319b3 ("nvme: fix admin request_queue lifetime").
CVSS
- Versión: 3.1
- Vector: CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
- Puntuación base: 5.5
Probabilidad de explotación (EPSS)
- Probabilidad de explotación en los próximos 30 días: 0.12%
- Percentil entre todas las CVEs puntuadas: 2
- Fecha de la puntuación: 6/10/2026
EPSS (Exploit Prediction Scoring System, de FIRST) estima la probabilidad de que una vulnerabilidad sea explotada en 30 días. Complementa a CVSS (impacto) y a CISA KEV (explotación confirmada).
Tecnologías afectadas (1)
CWE
- CWE-401
Referencias
- https://git.kernel.org/stable/c/089a6f17881a82c6c6e05f8564a867be0767eade
- https://git.kernel.org/stable/c/2efbc838a26d3da72d8fe05770bdf869d4ca3ac5
- https://git.kernel.org/stable/c/64f87b96de0e645a4c066c7cffd753f334446db6
- https://git.kernel.org/stable/c/6e28bab900e40e4d610b04f9f82e01983d8fb356
- https://git.kernel.org/stable/c/8eb2b3cdcd9b6631b94b82c1f4f6bc32b40d942f
- https://git.kernel.org/stable/c/b84bb7bd913d8ca2f976ee6faf4a174f91c02b8d
- https://git.kernel.org/stable/c/e159eb852aeee95443a9458ecb7d072bbb689913
JSON original (NVD)
Mostrar
{
"id": "CVE-2026-23360",
"cveTags": [],
"metrics": {
"cvssMetricV31": [
{
"type": "Primary",
"source": "nvd@nist.gov",
"cvssData": {
"scope": "UNCHANGED",
"version": "3.1",
"baseScore": 5.5,
"attackVector": "LOCAL",
"baseSeverity": "MEDIUM",
"vectorString": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H",
"integrityImpact": "NONE",
"userInteraction": "NONE",
"attackComplexity": "LOW",
"availabilityImpact": "HIGH",
"privilegesRequired": "LOW",
"confidentialityImpact": "NONE"
},
"impactScore": 3.6,
"exploitabilityScore": 1.8
}
]
},
"affected": [
{
"source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"affectedData": [
{
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"product": "Linux",
"versions": [
{
"status": "affected",
"version": "ff037b5f47eeccc1636c03f84cd47db094eb73c9",
"lessThan": "089a6f17881a82c6c6e05f8564a867be0767eade",
"versionType": "git"
},
{
"status": "affected",
"version": "4896491c497226022626c3acc46044fd182f943c",
"lessThan": "6e28bab900e40e4d610b04f9f82e01983d8fb356",
"versionType": "git"
},
{
"status": "affected",
"version": "a505f0ba36ab24176c300d7ff56aff85c2977e6c",
"lessThan": "2efbc838a26d3da72d8fe05770bdf869d4ca3ac5",
"versionType": "git"
},
{
"status": "affected",
"version": "e8061d02b49c5c901980f58d91e96580e9a14acf",
"lessThan": "64f87b96de0e645a4c066c7cffd753f334446db6",
"versionType": "git"
},
{
"status": "affected",
"version": "03b3bcd319b3ab5182bc9aaa0421351572c78ac0",
"lessThan": "e159eb852aeee95443a9458ecb7d072bbb689913",
"versionType": "git"
},
{
"status": "affected",
"version": "03b3bcd319b3ab5182bc9aaa0421351572c78ac0",
"lessThan": "8eb2b3cdcd9b6631b94b82c1f4f6bc32b40d942f",
"versionType": "git"
},
{
"status": "affected",
"version": "03b3bcd319b3ab5182bc9aaa0421351572c78ac0",
"lessThan": "b84bb7bd913d8ca2f976ee6faf4a174f91c02b8d",
"versionType": "git"
},
{
"status": "affected",
"version": "e7dac681790556c131854b97551337aa8042215b",
"versionType": "git"
},
{
"status": "affected",
"version": "6.1.167",
"lessThan": "6.1.168",
"versionType": "semver"
},
{
"status": "affected",
"version": "6.6.120",
"lessThan": "6.6.131",
"versionType": "semver"
},
{
"status": "affected",
"version": "6.12.62",
"lessThan": "6.12.77",
"versionType": "semver"
},
{
"status": "affected",
"version": "6.17.12",
"lessThan": "6.18",
"versionType": "semver"
}
],
"programFiles": [
"drivers/nvme/host/core.c"
],
"defaultStatus": "unaffected"
},
{
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"product": "Linux",
"versions": [
{
"status": "affected",
"version": "6.18"
},
{
"status": "unaffected",
"version": "0",
"lessThan": "6.18",
"versionType": "semver"
},
{
"status": "unaffected",
"version": "6.1.168",
"versionType": "semver",
"lessThanOrEqual": "6.1.*"
},
{
"status": "unaffected",
"version": "6.6.131",
"versionType": "semver",
"lessThanOrEqual": "6.6.*"
},
{
"status": "unaffected",
"version": "6.12.77",
"versionType": "semver",
"lessThanOrEqual": "6.12.*"
},
{
"status": "unaffected",
"version": "6.18.17",
"versionType": "semver",
"lessThanOrEqual": "6.18.*"
},
{
"status": "unaffected",
"version": "6.19.7",
"versionType": "semver",
"lessThanOrEqual": "6.19.*"
},
{
"status": "unaffected",
"version": "7.0",
"versionType": "original_commit_for_fix",
"lessThanOrEqual": "*"
}
],
"programFiles": [
"drivers/nvme/host/core.c"
],
"defaultStatus": "affected"
}
]
}
],
"published": "2026-03-25T11:16:34.907",
"references": [
{
"url": "https://git.kernel.org/stable/c/089a6f17881a82c6c6e05f8564a867be0767eade",
"tags": [
"Patch"
],
"source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
},
{
"url": "https://git.kernel.org/stable/c/2efbc838a26d3da72d8fe05770bdf869d4ca3ac5",
"tags": [
"Patch"
],
"source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
},
{
"url": "https://git.kernel.org/stable/c/64f87b96de0e645a4c066c7cffd753f334446db6",
"tags": [
"Patch"
],
"source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
},
{
"url": "https://git.kernel.org/stable/c/6e28bab900e40e4d610b04f9f82e01983d8fb356",
"tags": [
"Patch"
],
"source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
},
{
"url": "https://git.kernel.org/stable/c/8eb2b3cdcd9b6631b94b82c1f4f6bc32b40d942f",
"tags": [
"Patch"
],
"source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
},
{
"url": "https://git.kernel.org/stable/c/b84bb7bd913d8ca2f976ee6faf4a174f91c02b8d",
"tags": [
"Patch"
],
"source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
},
{
"url": "https://git.kernel.org/stable/c/e159eb852aeee95443a9458ecb7d072bbb689913",
"tags": [
"Patch"
],
"source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
}
],
"vulnStatus": "Analyzed",
"weaknesses": [
{
"type": "Primary",
"source": "nvd@nist.gov",
"description": [
{
"lang": "en",
"value": "CWE-401"
}
]
}
],
"descriptions": [
{
"lang": "en",
"value": "In the Linux kernel, the following vulnerability has been resolved:\n\nnvme: fix admin queue leak on controller reset\n\nWhen nvme_alloc_admin_tag_set() is called during a controller reset,\na previous admin queue may still exist. Release it properly before\nallocating a new one to avoid orphaning the old queue.\n\nThis fixes a regression introduced by commit 03b3bcd319b3 (\"nvme: fix\nadmin request_queue lifetime\")."
},
{
"lang": "es",
"value": "En el kernel de Linux, la siguiente vulnerabilidad ha sido resuelta:\n\nnvme: corrige la fuga de la cola de administración al reiniciar el controlador\n\nCuando se llama a nvme_alloc_admin_tag_set() durante un reinicio del controlador, una cola de administración anterior aún puede existir. Libérela correctamente antes de asignar una nueva para evitar dejar huérfana la cola antigua.\n\nEsto corrige una regresión introducida por el commit 03b3bcd319b3 ('nvme: corrige la vida útil de request_queue de administración')."
}
],
"lastModified": "2026-06-17T10:21:25.660",
"configurations": [
{
"nodes": [
{
"negate": false,
"cpeMatch": [
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "5A5BC13A-216B-45C3-A63E-D66C3FECFE85",
"versionEndExcluding": "6.6.131",
"versionStartIncluding": "6.6.120"
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "F861E4B9-708D-4A3E-9295-278B155F4550",
"versionEndExcluding": "6.12.77",
"versionStartIncluding": "6.12.62"
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "1FCE186E-ED64-4D23-A6C7-327D3D61F135",
"versionEndExcluding": "6.18",
"versionStartIncluding": "6.17.12"
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "07E9D8CD-82F0-4CC6-8038-BF71758D583C",
"versionEndExcluding": "6.18.17",
"versionStartIncluding": "6.18.1"
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "69245D10-0B71-485E-80C3-A64F077004D3",
"versionEndExcluding": "6.19.7",
"versionStartIncluding": "6.19"
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:6.1.167:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "B898A4FB-4E74-40F7-B523-B71FFB681B6D"
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:6.18:-:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "DCE57113-2223-4308-A0F2-5E6ECFBB3C23"
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:7.0:rc1:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "F253B622-8837-4245-BCE5-A7BF8FC76A16"
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:7.0:rc2:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "4AE85AD8-4641-4E7C-A2F4-305E2CD9EE64"
}
],
"operator": "OR"
}
]
}
],
"sourceIdentifier": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
}