Vulnerability Description
In the Linux kernel, the following vulnerability has been resolved: nvme: fix admin queue leak on controller reset When nvme_alloc_admin_tag_set() is called during a controller reset, a previous admin queue may still exist. Release it properly before allocating a new one to avoid orphaning the old queue. This fixes a regression introduced by commit 03b3bcd319b3 ("nvme: fix admin request_queue lifetime").
CVSS Score
MEDIUM
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Linux | Linux Kernel | >= 6.6.120, < 6.6.131 |
Related Weaknesses (CWE)
References
- https://git.kernel.org/stable/c/089a6f17881a82c6c6e05f8564a867be0767eadePatch
- https://git.kernel.org/stable/c/2efbc838a26d3da72d8fe05770bdf869d4ca3ac5Patch
- https://git.kernel.org/stable/c/64f87b96de0e645a4c066c7cffd753f334446db6Patch
- https://git.kernel.org/stable/c/6e28bab900e40e4d610b04f9f82e01983d8fb356Patch
- https://git.kernel.org/stable/c/8eb2b3cdcd9b6631b94b82c1f4f6bc32b40d942fPatch
- https://git.kernel.org/stable/c/b84bb7bd913d8ca2f976ee6faf4a174f91c02b8dPatch
- https://git.kernel.org/stable/c/e159eb852aeee95443a9458ecb7d072bbb689913Patch
FAQ
What is CVE-2026-23360?
CVE-2026-23360 is a vulnerability with a CVSS score of 5.5 (MEDIUM). In the Linux kernel, the following vulnerability has been resolved: nvme: fix admin queue leak on controller reset When nvme_alloc_admin_tag_set() is called during a controller reset, a previous adm...
How severe is CVE-2026-23360?
CVE-2026-23360 has been rated MEDIUM with a CVSS base score of 5.5/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2026-23360?
Check the references section above for vendor advisories and patch information. Affected products include: Linux Linux Kernel.