← All Advisories

CVE-2026-98056

Last refreshed2026-10-10

Status: UPDATED  |  Advisory ID: CVE-2026-98056

Key Details

CVECVE-2026-98056
CVSS Score / Version7.5 (High) / CVSS v3.1
Updated2026-09-30
CVSS VectorCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
CVSS Proseattack vector is network; attack complexity is low; privileges required is none; user interaction is none; scope is unchanged; confidentiality impact is none; integrity impact is none; availability impact is high.
Affected productsLinux Kernel

Affected Products, Subsystems & Sectors

VendorProductAffected VersionsPatch Status
LinuxLinux Kernel
SubsystemsOT Supporting Infrastructure
SectorsAll Sectors

What to Know

In the Linux kernel, the following vulnerability has been resolved:

nvme: remove stale namespaces by NSID range during scan

nvme_scan_ns_list() drops the stale namespaces in each gap in the

reported NSID list one NSID at a time. Every iteration calls

nvme_find_get_ns() to look the namespace up and removes it if it is

present. The loop runs once per NSID in the gap rather than once per

namespace actually present.

NSIDs are 32-bit, so a target with a sparse NSID space can make a

single gap spin the loop billions of times with nothing to remove.

watchdog: BUG: soft lockup - CPU#4 stuck for 26s!

Workqueue: nvme-wq nvme_scan_work [nvme_core]

RIP: 0010:__srcu_read_unlock+0xb/0x20

Call Trace:

nvme_find_get_ns+0x7d/0xb0 [nvme_core]

nvme_scan_ns_list+0xe8/0x280 [nvme_core]

nvme_scan_work+0x18a/0x280 [nvme_core]

process_one_work+0x197/0x380

worker_thread+0x2fe/0x410

kthread+0xe0/0x100

Rename nvme_remove_invalid_namespaces() to nvme_remove_nsid_range()

and give it an open (start, end) NSID range. ctrl->namespaces is

sorted by NSID, so the whole gap is dropped in a single walk that

stops once end is reached. This bounds the work by the namespaces

that are present instead of by the size of the gap. (NVD)

What to Do

Monitor Linux's web page for any future patch releases.

References

SourceReference
NVDhttps://nvd.nist.gov/vuln/detail/CVE-2026-98056
CVEhttps://www.cve.org/CVERecord?id=CVE-2026-98056