cbcvebase.
CVE-2026-46304
published 2026-06-08

CVE-2026-46304: In the Linux kernel, the following vulnerability has been resolved: nvmet: avoid recursive nvmet-wq flush in nvmet_ctrl_free nvmet_tcp_release_queue_work()…

PriorityP340high7.5CVSS 3.1
AVNACLPRNUINSUCNINAH
EPSS
0.39%
31.2th percentile
In the Linux kernel, the following vulnerability has been resolved: nvmet: avoid recursive nvmet-wq flush in nvmet_ctrl_free nvmet_tcp_release_queue_work() runs on nvmet-wq and can drop the final controller reference through nvmet_cq_put(). If that triggers nvmet_ctrl_free(), the teardown path flushes ctrl->async_event_work on the same nvmet-wq. Call chain: nvmet_tcp_schedule_release_queue() kref_put(&queue->kref, nvmet_tcp_release_queue) nvmet_tcp_release_queue() queue_work(nvmet_wq, &queue->release_work) nvme_cq) nvmet_cq_destroy() nvmet_ctrl_put(cq->ctrl) nvmet_ctrl_free() flush_work(&ctrl->async_event_work) async_event_work); This trips lockdep with a possible recursive locking warning. [ 5223.015876] run blktests nvme/003 at 2026-04-07 20:53:55 [ 5223.061801] loop0: detected capacity change from 0 to 2097152 [ 5223.072206] nvmet: adding nsid 1 to subsystem blktests-subsystem-1 [ 5223.088368] nvmet_tcp: enabling port 0 (127.0.0.1:4420) [ 5223.126086] nvmet: Created discovery controller 1 for subsystem nqn.2014-08.org.nvmexpress.discovery for NQN nqn.2014-08.org.nvmexpress:uuid:0f01fb42-9f7f-4856-b0b3-51e60b8de349. [ 5223.128453] nvme nvme1: new ctrl: NQN "nqn.2014-08.org.nvmexpress.discovery", addr 127.0.0.1:4420, hostnqn: nqn.2014-08.org.nvmexpress:uuid:0f01fb42-9f7f-4856-b0b3-51e60b8de349 [ 5233.199447] nvme nvme1: Removing ctrl: NQN "nqn.2014-08.org.nvmexpress.discovery" [ 5233.227718] ============================================ [ 5233.231283] WARNING: possible recursive locking detected [ 5233.234696] 7.0.0-rc3nvme+ #20 Tainted: G O N [ 5233.238434] -------------------------------------------- [ 5233.241852] kworker/u192:6/2413 is trying to acquire lock: [ 5233.245429] ffff888111632548 ((wq_completion)nvmet-wq){+.+.}-{0:0}, at: touch_wq_lockdep_map+0x26/0x90 [ 5233.251438] but task is already holding lock: [ 5233.255254] ffff888111632548 ((wq_completion)nvmet-wq){+.+.}-{0:0}, at: process_one_work+0x5cc/0x6e0 [ 5233.261125] other info that might help

Affected

25 ranges
VendorProductVersion rangeFixed in
linuxlinux
linuxlinux
linuxlinux>= 06406d81a2d7cfb8abcc4fa6cdfeb8e5897007c5 < ae5b0cad163833e10b271e9becc05d81dae56e5fae5b0cad163833e10b271e9becc05d81dae56e5f
linuxlinux>= 06406d81a2d7cfb8abcc4fa6cdfeb8e5897007c5 < 8d66ba89480ff098a58d79003a505f383aa4e9208d66ba89480ff098a58d79003a505f383aa4e920
linuxlinux>= 06406d81a2d7cfb8abcc4fa6cdfeb8e5897007c5 < a696fbbd5240b4ac9b166f7bd4c550882ff543f1a696fbbd5240b4ac9b166f7bd4c550882ff543f1
linuxlinux>= 06406d81a2d7cfb8abcc4fa6cdfeb8e5897007c5 < 9a4d7222c0955b221e38bb66d10e6bccb672c8a19a4d7222c0955b221e38bb66d10e6bccb672c8a1
linuxlinux>= 06406d81a2d7cfb8abcc4fa6cdfeb8e5897007c5 < ee6e20c4bc9eae542a0954a368449532383169d4ee6e20c4bc9eae542a0954a368449532383169d4
linuxlinux>= 06406d81a2d7cfb8abcc4fa6cdfeb8e5897007c5 < 781f47d641432c26c19625b2cdd7f40825097592781f47d641432c26c19625b2cdd7f40825097592
linuxlinux>= 06406d81a2d7cfb8abcc4fa6cdfeb8e5897007c5 < 551f445a56a11a6457550cddcf39c9ebb8bcacc6551f445a56a11a6457550cddcf39c9ebb8bcacc6
linuxlinux>= 06406d81a2d7cfb8abcc4fa6cdfeb8e5897007c5 < aade8abd8b868b6ffa9697aadaea28ec7f65bee6aade8abd8b868b6ffa9697aadaea28ec7f65bee6
linuxlinux>= 4.9.68 < 4.104.10
linuxlinux_kernel
linuxlinux_kernel
linuxlinux_kernel
linuxlinux_kernel
linuxlinux_kernel
linuxlinux_kernel
linuxlinux_kernel>= 4.10.1 < 5.10.2585.10.258
linuxlinux_kernel>= 4.9.68 < 4.104.10
linuxlinux_kernel>= 5.11 < 5.15.2095.15.209
linuxlinux_kernel>= 5.16 < 6.1.1756.1.175
linuxlinux_kernel>= 6.13 < 6.18.306.18.30
linuxlinux_kernel>= 6.19 < 7.0.77.0.7
linuxlinux_kernel>= 6.2 < 6.6.1406.6.140
linuxlinux_kernel>= 6.7 < 6.12.886.12.88

CVSS provenance

nvdv3.17.5HIGHCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
vendor_redhat5.5MEDIUM
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.