OCTOBER 7, 2026
Live Feed
Back to database
Case File

CVE-2026-89970

CRITICAL · CVSS 9.8 EPSS 0.85%

Source: NVD + CISA KEV + EPSS · Published 2026-09-16 · Last synced 2026-10-07

CyberRota Analysis

AI-Generated

The vulnerability affects the Linux kernel's nvmet-auth module, specifically during the teardown of submission queues (SQ), where improper synchronization can lead to use-after-free conditions. This could allow an attacker to exploit the race condition, potentially leading to unauthorized access or system instability. Organizations using Linux systems with nvmet-auth should prioritize this fix to mitigate the risk of exploitation.

CVE
CVE-2026-89970
Severity
CRITICAL
CVSS
9.8
EPSS
0.85%
Linux

Original NVD Description

In the Linux kernel, the following vulnerability has been resolved: nvmet-auth: Synchronize timeout work during SQ teardown nvmet_auth_sq_free() cancels auth_expired_work with cancel_delayed_work(). If the work has already started, cancellation does not wait for the callback. Transport teardown can consequently free or reuse the queue containing struct nvmet_sq while nvmet_auth_expired_work() still accesses that SQ. Add a teardown-specific helper that synchronously drains the delayed work before freeing authentication state, and use it from nvmet_sq_destroy(). Keep the non-synchronous helper for in-band authentication state cleanup, where the SQ owner remains alive.