cbcvebase.
CVE-2026-23261
published 2026-03-18

CVE-2026-23261: In the Linux kernel, the following vulnerability has been resolved: nvme-fc: release admin tagset if init fails nvme_fabrics creates an NVMe/FC controller in…

PriorityP420medium5.5CVSS 3.1
AVLACLPRLUINSUCNINAH
EPSS
0.11%
1.7th percentile
In the Linux kernel, the following vulnerability has been resolved: nvme-fc: release admin tagset if init fails nvme_fabrics creates an NVMe/FC controller in following path: nvmf_dev_write() -> nvmf_create_ctrl() -> nvme_fc_create_ctrl() -> nvme_fc_init_ctrl() nvme_fc_init_ctrl() allocates the admin blk-mq resources right after nvme_add_ctrl() succeeds. If any of the subsequent steps fail (changing the controller state, scheduling connect work, etc.), we jump to the fail_ctrl path, which tears down the controller references but never frees the admin queue/tag set. The leaked blk-mq allocations match the kmemleak report seen during blktests nvme/fc. Check ctrl->ctrl.admin_tagset in the fail_ctrl path and call nvme_remove_admin_tag_set() when it is set so that all admin queue allocations are reclaimed whenever controller setup aborts.

Affected

45 ranges· showing 25
VendorProductVersion rangeFixed in
debianlinux< linux 6.18.10-1 (forky)linux 6.18.10-1 (forky)
linuxlinux
linuxlinux
linuxlinux>= 17c3a66d7ea2d303f783796d62f99e2e23b68c90 < fa301aef50e3f3b5be6ee53457608beae5aa7a01fa301aef50e3f3b5be6ee53457608beae5aa7a01
linuxlinux>= 5fe335a80548e2eda5d51fab801108b323600e95 < 7c54d3f5ebbc5982daaa004260242dc07ac943ea7c54d3f5ebbc5982daaa004260242dc07ac943ea
linuxlinux>= 6.12.60 < 6.12.706.12.70
linuxlinux>= 6.17.10 < 6.186.18
linuxlinux>= 6.6.118 < 6.6.1246.6.124
linuxlinux>= ea3442efabd0aa3930c5bab73c3901ef38ef6ac3 < e810b290922c535feb34bc90ab549446fe94d2a3e810b290922c535feb34bc90ab549446fe94d2a3
linuxlinux>= ea3442efabd0aa3930c5bab73c3901ef38ef6ac3 < d1877cc7270302081a315a81a0ee8331f19f95c8d1877cc7270302081a315a81a0ee8331f19f95c8
linuxlinux_kernel
linuxlinux_kernel
linuxlinux_kernel>= 0 < 6.12.73-16.12.73-1
linuxlinux_kernel>= 0 < 6.18.10-16.18.10-1
linuxlinux_kernel>= 0 < 6.6.1246.6.124
linuxlinux_kernel>= 6.12.60 < 6.12.706.12.70
linuxlinux_kernel>= 6.13.0 < 6.18.106.18.10
linuxlinux_kernel>= 6.17.10 < 6.186.18
linuxlinux_kernel>= 6.18.1 < 6.18.106.18.10
linuxlinux_kernel>= 6.6.118 < 6.6.1246.6.124
linuxlinux_kernel>= 6.7.0 < 6.12.706.12.70
ubuntulinux
ubuntulinux-aws
ubuntulinux-aws-fips
ubuntulinux-azure

CVSS provenance

nvdv3.15.5MEDIUMCVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
vendor_ubuntu7.8HIGH
vendor_redhat3.3LOW
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.