OCTOBER 9, 2026
Live Feed
Back to database
Case File

CVE-2026-98154

HIGH · CVSS 7 EPSS 0.11%

Source: NVD + CISA KEV + EPSS · Published 2026-09-25 · Last synced 2026-10-09

CyberRota Analysis

AI-Generated

The vulnerability affects the Linux kernel's NVMe over RDMA implementation, specifically in the error handling process during command execution. An improper cleanup order can lead to a double cleanup and potential data integrity issues, which may compromise system stability. Organizations using Linux systems with RDMA capabilities should prioritize this fix to ensure reliable operation and prevent potential data loss.

CVE
CVE-2026-98154
Severity
HIGH
CVSS
7
EPSS
0.11%
Linux

Original NVD Description

In the Linux kernel, the following vulnerability has been resolved: nvme-rdma: fix -EIO cleanup order in queue_rq On -EIO, the RDMA queue_rq path reports a host path error and then still cleans up the command and unmaps the SQE DMA. The path error helper completes the request, so that is double cleanup and DMA unmap after the request is already complete. Unmap the SQE first, then report the host path error. Skip the outer command cleanup on that path.