CVE-2026-46304
published 2026-06-08CVE-2026-46304: In the Linux kernel, the following vulnerability has been resolved: nvmet: avoid recursive nvmet-wq flush in nvmet_ctrl_free nvmet_tcp_release_queue_work()…
PriorityP340high7.5CVSS 3.1
AVNACLPRNUINSUCNINAH
EPSS
0.39%
31.2th percentile
In the Linux kernel, the following vulnerability has been resolved:
nvmet: avoid recursive nvmet-wq flush in nvmet_ctrl_free
nvmet_tcp_release_queue_work() runs on nvmet-wq and can drop the
final controller reference through nvmet_cq_put(). If that triggers
nvmet_ctrl_free(), the teardown path flushes ctrl->async_event_work on
the same nvmet-wq.
Call chain:
nvmet_tcp_schedule_release_queue()
kref_put(&queue->kref, nvmet_tcp_release_queue)
nvmet_tcp_release_queue()
queue_work(nvmet_wq, &queue->release_work) nvme_cq)
nvmet_cq_destroy()
nvmet_ctrl_put(cq->ctrl)
nvmet_ctrl_free()
flush_work(&ctrl->async_event_work) async_event_work);
This trips lockdep with a possible recursive locking warning.
[ 5223.015876] run blktests nvme/003 at 2026-04-07 20:53:55
[ 5223.061801] loop0: detected capacity change from 0 to 2097152
[ 5223.072206] nvmet: adding nsid 1 to subsystem blktests-subsystem-1
[ 5223.088368] nvmet_tcp: enabling port 0 (127.0.0.1:4420)
[ 5223.126086] nvmet: Created discovery controller 1 for subsystem nqn.2014-08.org.nvmexpress.discovery for NQN nqn.2014-08.org.nvmexpress:uuid:0f01fb42-9f7f-4856-b0b3-51e60b8de349.
[ 5223.128453] nvme nvme1: new ctrl: NQN "nqn.2014-08.org.nvmexpress.discovery", addr 127.0.0.1:4420, hostnqn: nqn.2014-08.org.nvmexpress:uuid:0f01fb42-9f7f-4856-b0b3-51e60b8de349
[ 5233.199447] nvme nvme1: Removing ctrl: NQN "nqn.2014-08.org.nvmexpress.discovery"
[ 5233.227718] ============================================
[ 5233.231283] WARNING: possible recursive locking detected
[ 5233.234696] 7.0.0-rc3nvme+ #20 Tainted: G O N
[ 5233.238434] --------------------------------------------
[ 5233.241852] kworker/u192:6/2413 is trying to acquire lock:
[ 5233.245429] ffff888111632548 ((wq_completion)nvmet-wq){+.+.}-{0:0}, at: touch_wq_lockdep_map+0x26/0x90
[ 5233.251438]
but task is already holding lock:
[ 5233.255254] ffff888111632548 ((wq_completion)nvmet-wq){+.+.}-{0:0}, at: process_one_work+0x5cc/0x6e0
[ 5233.261125]
other info that might help
Affected
25 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| linux | linux | — | — |
| linux | linux | — | — |
| linux | linux | >= 06406d81a2d7cfb8abcc4fa6cdfeb8e5897007c5 < ae5b0cad163833e10b271e9becc05d81dae56e5f | ae5b0cad163833e10b271e9becc05d81dae56e5f |
| linux | linux | >= 06406d81a2d7cfb8abcc4fa6cdfeb8e5897007c5 < 8d66ba89480ff098a58d79003a505f383aa4e920 | 8d66ba89480ff098a58d79003a505f383aa4e920 |
| linux | linux | >= 06406d81a2d7cfb8abcc4fa6cdfeb8e5897007c5 < a696fbbd5240b4ac9b166f7bd4c550882ff543f1 | a696fbbd5240b4ac9b166f7bd4c550882ff543f1 |
| linux | linux | >= 06406d81a2d7cfb8abcc4fa6cdfeb8e5897007c5 < 9a4d7222c0955b221e38bb66d10e6bccb672c8a1 | 9a4d7222c0955b221e38bb66d10e6bccb672c8a1 |
| linux | linux | >= 06406d81a2d7cfb8abcc4fa6cdfeb8e5897007c5 < ee6e20c4bc9eae542a0954a368449532383169d4 | ee6e20c4bc9eae542a0954a368449532383169d4 |
| linux | linux | >= 06406d81a2d7cfb8abcc4fa6cdfeb8e5897007c5 < 781f47d641432c26c19625b2cdd7f40825097592 | 781f47d641432c26c19625b2cdd7f40825097592 |
| linux | linux | >= 06406d81a2d7cfb8abcc4fa6cdfeb8e5897007c5 < 551f445a56a11a6457550cddcf39c9ebb8bcacc6 | 551f445a56a11a6457550cddcf39c9ebb8bcacc6 |
| linux | linux | >= 06406d81a2d7cfb8abcc4fa6cdfeb8e5897007c5 < aade8abd8b868b6ffa9697aadaea28ec7f65bee6 | aade8abd8b868b6ffa9697aadaea28ec7f65bee6 |
| linux | linux | >= 4.9.68 < 4.10 | 4.10 |
| linux | linux_kernel | — | — |
| linux | linux_kernel | — | — |
| linux | linux_kernel | — | — |
| linux | linux_kernel | — | — |
| linux | linux_kernel | — | — |
| linux | linux_kernel | — | — |
| linux | linux_kernel | >= 4.10.1 < 5.10.258 | 5.10.258 |
| linux | linux_kernel | >= 4.9.68 < 4.10 | 4.10 |
| linux | linux_kernel | >= 5.11 < 5.15.209 | 5.15.209 |
| linux | linux_kernel | >= 5.16 < 6.1.175 | 6.1.175 |
| linux | linux_kernel | >= 6.13 < 6.18.30 | 6.18.30 |
| linux | linux_kernel | >= 6.19 < 7.0.7 | 7.0.7 |
| linux | linux_kernel | >= 6.2 < 6.6.140 | 6.6.140 |
| linux | linux_kernel | >= 6.7 < 6.12.88 | 6.12.88 |
CVSS provenance
nvdv3.17.5HIGHCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
vendor_redhat5.5MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Red Hat
kernel: nvmet: avoid recursive nvmet-wq flush in nvmet_ctrl_free
vendor_redhat·2026-06-08·CVSS 5.5
CVE-2026-46304 [MEDIUM] CWE-833 kernel: nvmet: avoid recursive nvmet-wq flush in nvmet_ctrl_free
kernel: nvmet: avoid recursive nvmet-wq flush in nvmet_ctrl_free
A flaw was found in the Linux kernel's NVMe over TCP (nvmet) target subsystem. A recursive locking issue can occur when `nvmet_tcp_release_queue_work()` attempts to flush `ctrl->async_event_work` on the same workqueue (`nvmet-wq`) that is already processing a task. This can lead to a deadlock, causing a Denial of Service (DoS) condition for the system.
Package: kernel (Red Hat Enterprise Linux 10) - Fix deferred
Package: kernel (Red Hat Enterprise Linux 6) - Not affected
Package: kernel (Red Hat Enterprise Linux 7) - Fix deferred
Package: kernel-rt (Red Hat Enterprise Linux 7) - Fix deferred
Package: kernel (Red Hat Enterprise Linux 8) - Fix deferred
Package: kernel-rt (Red Hat Enterprise Linux 8) - Fix deferred
Packa
GHSA
In the Linux kernel, the following vulnerability has been resolved: nvmet: avoid recursive nvmet-wq flush in nvmet_ctrl_free nvmet_tcp_release_queue_work() runs on nvmet-wq and can drop the final co
ghsa_unreviewed·2026-06-08
CVE-2026-46304 In the Linux kernel, the following vulnerability has been resolved: nvmet: avoid recursive nvmet-wq flush in nvmet_ctrl_free nvmet_tcp_release_queue_work() runs on nvmet-wq and can drop the final co
In the Linux kernel, the following vulnerability has been resolved:
nvmet: avoid recursive nvmet-wq flush in nvmet_ctrl_free
nvmet_tcp_release_queue_work() runs on nvmet-wq and can drop the
final controller reference through nvmet_cq_put(). If that triggers
nvmet_ctrl_free(), the teardown path flushes ctrl->async_event_work on
the same nvmet-wq.
Call chain:
nvmet_tcp_schedule_release_queue()
kref_put(&queue->kref, nvmet_tcp_release_queue)
nvmet_tcp_release_queue()
queue_work(nvmet_wq, &queue->release_work) nvme_cq)
nvmet_cq_destroy()
nvmet_ctrl_put(cq->ctrl)
nvmet_ctrl_free()
flush_work(&ctrl->async_event_work) async_event_work);
This trips lockdep with a possible recursive locking warning.
[ 5223.015876] run blktests nvme/003 at 2026-04-07 20:53:55
[ 5223.061801] loop0: detected cap
VulDB
Linux Kernel up to 7.1-rc1 nvmet nvmet_tcp_release_queue_work async_event_work deadlock
vuldb·2026-06-08
CVE-2026-46304 [CRITICAL] Linux Kernel up to 7.1-rc1 nvmet nvmet_tcp_release_queue_work async_event_work deadlock
A vulnerability classified as critical has been found in Linux Kernel up to 7.1-rc1. Affected by this issue is the function nvmet_tcp_release_queue_work of the component nvmet. Performing a manipulation of the argument async_event_work results in deadlock.
This vulnerability is cataloged as CVE-2026-46304. The attack must originate from the local network. There is no exploit available.
It is recommended to upgrade the affected component.
No detection rules found.
No public exploits indexed.
https://git.kernel.org/stable/c/551f445a56a11a6457550cddcf39c9ebb8bcacc6https://git.kernel.org/stable/c/781f47d641432c26c19625b2cdd7f40825097592https://git.kernel.org/stable/c/8d66ba89480ff098a58d79003a505f383aa4e920https://git.kernel.org/stable/c/9a4d7222c0955b221e38bb66d10e6bccb672c8a1https://git.kernel.org/stable/c/a696fbbd5240b4ac9b166f7bd4c550882ff543f1https://git.kernel.org/stable/c/aade8abd8b868b6ffa9697aadaea28ec7f65bee6https://git.kernel.org/stable/c/ae5b0cad163833e10b271e9becc05d81dae56e5fhttps://git.kernel.org/stable/c/ee6e20c4bc9eae542a0954a368449532383169d4
2026-06-08
Published