Direct naar de inhoud
⚡ Kritieke cyberalerts voor jouw sector & systemen — direct in je inbox. Aanmelden →
cybernieuws.nl Cybersecurity en informatiebeveiling nieuws alerts live · 11 min 139 bronnen 1 kritiek 5 vandaag
CVE's Videos Dagbriefing

← Terug naar CVE-database

CVE-2026-98154

HIGH · 7.0 CVSS Gepubliceerd:

Beschrijving NL

In de Linux-kernel is de volgende kwetsbaarheid verholpen:

nvme-rdma: fix -EIO cleanup order in queue_rq

Bij -EIO meldt het RDMA queue_rq-pad een hostpadfout en vervolgens
Het commando wordt nog steeds opgeschoond en de SQE DMA wordt ontkoppeld. De padfout
De helper voltooit het verzoek, dus dat is dubbele opschoning en DMA-ontkoppeling.
nadat het verzoek al is voltooid.

Ontkoppel eerst de SQE en meld vervolgens de hostpadfout. Sla de buitenste stap over.
Voer het commando 'cleanup' uit op dat pad.

Origineel (Engels) tonen

In the Linux kernel, the following vulnerability has been resolved:

nvme-rdma: fix -EIO cleanup order in queue_rq

On -EIO, the RDMA queue_rq path reports a host path error and then
still cleans up the command and unmaps the SQE DMA. The path error
helper completes the request, so that is double cleanup and DMA unmap
after the request is already complete.

Unmap the SQE first, then report the host path error. Skip the outer
command cleanup on that path.

References