AUGUST 15, 2026
Live Feed
Back to database
Case File

CVE-2026-72128

UNKNOWN · CVSS N/A

Source: NVD + CISA KEV + EPSS · Published 2026-08-15 · Last synced 2026-08-15

CyberRota Analysis

AI-Generated

The vulnerability affects the Linux kernel's nvmet subsystem, specifically in the nvmet_sq_create() function, where a reference count leak occurs if nvmet_check_sqid() fails. This can lead to resource exhaustion over time, potentially impacting system stability and performance. Administrators of Linux systems utilizing the nvmet feature should prioritize applying the fix to mitigate this risk.

CVE
CVE-2026-72128
Severity
UNKNOWN
CVSS
N/A
EPSS
N/A
Linux

Original NVD Description

In the Linux kernel, the following vulnerability has been resolved: nvmet: fix refcount leak in nvmet_sq_create() In nvmet_sq_create(), a reference on the ctrl is taken via kref_get_unless_zero() before calling nvmet_check_sqid(). If nvmet_check_sqid() fails, the function returns the error directly without releasing the reference, leading to a leak. Fix this by jumping to the "ctrl_put" label, which already performs the necessary nvmet_ctrl_put(ctrl). This ensures the reference is properly released on this error path.