{"dataType":"CVE_RECORD","dataVersion":"5.2","cveMetadata":{"cveId":"CVE-2026-89970","assignerOrgId":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","state":"PUBLISHED","assignerShortName":"Linux","dateReserved":"2026-09-11T19:38:34.778Z","datePublished":"2026-09-16T10:32:50.306Z","dateUpdated":"2026-09-16T14:40:49.745Z"},"containers":{"cna":{"providerMetadata":{"orgId":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","shortName":"Linux","dateUpdated":"2026-09-16T14:40:49.745Z"},"descriptions":[{"lang":"en","value":"In the Linux kernel, the following vulnerability has been resolved:\n\nnvmet-auth: Synchronize timeout work during SQ teardown\n\nnvmet_auth_sq_free() cancels auth_expired_work with\ncancel_delayed_work(). If the work has already started, cancellation does\nnot wait for the callback. Transport teardown can consequently free or\nreuse the queue containing struct nvmet_sq while\nnvmet_auth_expired_work() still accesses that SQ.\n\nAdd a teardown-specific helper that synchronously drains the delayed work\nbefore freeing authentication state, and use it from nvmet_sq_destroy().\nKeep the non-synchronous helper for in-band authentication state cleanup,\nwhere the SQ owner remains alive."}],"metrics":[{"cvssV3_1":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H","baseScore":9.8,"baseSeverity":"CRITICAL"},"scenarios":[{"lang":"en","value":"AV:N - The UAF is in nvmet-auth timeout work reached via AUTH_SEND on NVMe-oF targets; nvmet-tcp (and nvmet-rdma) accept remote connections, so a network initiator can arm the timer and tear down the queue over TCP/RDMA.\nAC:L - The attacker controls both sides of the race: AUTH_SEND schedules auth_expired_work with an attacker-chosen KATO delay, and closing the connection runs nvmet_sq_destroy(); cancel_delayed_work() does not wait, so the race is repeatable.\nPR:N - AUTH_SEND is dispatched as a Fabrics command before nvmet_check_auth_status() and before DH-HMAC-CHAP credentials are verified; discovery accepts any host NQN, so no Linux privileges or verified secrets are required.\nUI:N - No victim user action is required; the attacker connects to an already-deployed NVMe-oF target, sends AUTH_SEND to arm the timeout, and disconnects when the work is due.\nS:U - The use-after-free corrupts the in-kernel nvmet_sq/queue object on the target host and does not cross a VM, hypervisor, or IOMMU security boundary.\nC:H - Transport teardown can free or reuse the queue containing struct nvmet_sq while nvmet_auth_expired_work() still accesses it; that UAF can be leveraged for kernel information disclosure via heap reuse.\nI:H - The delayed work writes dhchap_step and dhchap_tid into a potentially freed or reused queue object, giving a kernel UAF write primitive exploitable for memory corruption and control-flow hijacking.\nA:H - Racing the timeout callback against SQ teardown is a kernel UAF of the queue and can oops or panic; the work may also dereference sq->ctrl after teardown has already cleared it."}]}],"affected":[{"product":"Linux","vendor":"Linux","defaultStatus":"unaffected","repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","programFiles":["drivers/nvme/target/auth.c","drivers/nvme/target/core.c","drivers/nvme/target/nvmet.h"],"versions":[{"version":"1a70200f404ae210b4f0334e3936e84f8edb6bc8","lessThan":"664022fa1c93f4eba09ef5ee02411b9709dd7a93","status":"affected","versionType":"git"},{"version":"1a70200f404ae210b4f0334e3936e84f8edb6bc8","lessThan":"c3c126a6142a1335bc8c34a5607c39cf01daf295","status":"affected","versionType":"git"},{"version":"1a70200f404ae210b4f0334e3936e84f8edb6bc8","lessThan":"c17c87bde6d6f5252a6a6f0a94b2430164aa28d5","status":"affected","versionType":"git"},{"version":"1a70200f404ae210b4f0334e3936e84f8edb6bc8","lessThan":"7555ddd60af72df2862dd8f9b730a9848577edda","status":"affected","versionType":"git"},{"version":"1a70200f404ae210b4f0334e3936e84f8edb6bc8","lessThan":"eb4f9127a2b8a152743f1ee597627e2f69cb54fe","status":"affected","versionType":"git"},{"version":"1a70200f404ae210b4f0334e3936e84f8edb6bc8","lessThan":"eaa948c0e19b1bb2d93262207bca0c3d19cc3406","status":"affected","versionType":"git"}]},{"product":"Linux","vendor":"Linux","defaultStatus":"affected","repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","programFiles":["drivers/nvme/target/auth.c","drivers/nvme/target/core.c","drivers/nvme/target/nvmet.h"],"versions":[{"version":"6.0","status":"affected"},{"version":"0","lessThan":"6.0","status":"unaffected","versionType":"semver"},{"version":"6.1.188","lessThanOrEqual":"6.1.*","status":"unaffected","versionType":"semver"},{"version":"6.6.157","lessThanOrEqual":"6.6.*","status":"unaffected","versionType":"semver"},{"version":"6.12.110","lessThanOrEqual":"6.12.*","status":"unaffected","versionType":"semver"},{"version":"6.18.51","lessThanOrEqual":"6.18.*","status":"unaffected","versionType":"semver"},{"version":"7.2.5","lessThanOrEqual":"7.2.*","status":"unaffected","versionType":"semver"},{"version":"7.3-rc2","lessThanOrEqual":"*","status":"unaffected","versionType":"original_commit_for_fix"}]}],"cpeApplicability":[{"nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*","versionStartIncluding":"6.0","versionEndExcluding":"6.1.188"},{"vulnerable":true,"criteria":"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*","versionStartIncluding":"6.0","versionEndExcluding":"6.6.157"},{"vulnerable":true,"criteria":"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*","versionStartIncluding":"6.0","versionEndExcluding":"6.12.110"},{"vulnerable":true,"criteria":"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*","versionStartIncluding":"6.0","versionEndExcluding":"6.18.51"},{"vulnerable":true,"criteria":"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*","versionStartIncluding":"6.0","versionEndExcluding":"7.2.5"},{"vulnerable":true,"criteria":"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*","versionStartIncluding":"6.0","versionEndExcluding":"7.3-rc2"}]}]}],"references":[{"url":"https://git.kernel.org/stable/c/664022fa1c93f4eba09ef5ee02411b9709dd7a93"},{"url":"https://git.kernel.org/stable/c/c3c126a6142a1335bc8c34a5607c39cf01daf295"},{"url":"https://git.kernel.org/stable/c/c17c87bde6d6f5252a6a6f0a94b2430164aa28d5"},{"url":"https://git.kernel.org/stable/c/7555ddd60af72df2862dd8f9b730a9848577edda"},{"url":"https://git.kernel.org/stable/c/eb4f9127a2b8a152743f1ee597627e2f69cb54fe"},{"url":"https://git.kernel.org/stable/c/eaa948c0e19b1bb2d93262207bca0c3d19cc3406"}],"title":"nvmet-auth: Synchronize timeout work during SQ teardown","x_generator":{"engine":"bippy-1.2.0"}}}}