CyberRota Analysis
AI-GeneratedThe vulnerability affects the Linux kernel's NVMe subsystem, specifically in the error handling of namespace allocation, where the system fails to wait for concurrent readers before freeing a namespace structure. This oversight could lead to use-after-free conditions, potentially causing system instability or crashes when multipath operations are performed. Organizations utilizing Linux systems with NVMe storage should prioritize addressing this issue to maintain system reliability and prevent potential disruptions.
Original NVD Description
In the Linux kernel, the following vulnerability has been resolved: nvme: add missing SRCU grace period in error path nvme_alloc_ns() error path at out_unlink_ns removes ns from the namespace head siblings list with list_del_rcu(&ns->siblings) but does not wait for SRCU readers before freeing the namespace struct. Multipath code iterates the head->list under srcu_read_lock() in nvme_find_path() and nvme_mpath_revalidate_paths(), so a concurrent reader can still hold a reference to ns when kfree(ns) runs. The normal removal path in nvme_ns_remove() correctly calls synchronize_srcu(&ns->head->srcu) after list_del_rcu() to wait for in-progress readers. Add the same grace period in the error path.