CVE-2026-64321

Source
https://cve.org/CVERecord?id=CVE-2026-64321
Import Source
https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-64321.json
JSON Data
https://api.osv.dev/v1/vulns/CVE-2026-64321
Downstream
Related
Published
2026-07-25T08:49:49Z
Modified
2026-09-16T03:30:32Z
Summary
nvme: target: rdma: fix ndev refcount leak on queue connect
Details

In the Linux kernel, the following vulnerability has been resolved:

nvme: target: rdma: fix ndev refcount leak on queue connect

nvmet_rdma_queue_connect() calls nvmet_rdma_find_get_device() which acquires a reference on the returned ndev via kref_get(). On the path where the host queue backlog is exceeded and the function returns NVME_SC_CONNECT_CTRL_BUSY, reference of ndev is not released, leaking the kref.

Fix this by adding a goto to the existing put_device label before the early return.

Database specific
{
    "cna_assigner": "Linux",
    "osv_generated_from": "https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/64xxx/CVE-2026-64321.json"
}
References

Affected packages

Git / git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git

Affected ranges

Type
GIT
Repo
https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git
Events
Introduced
28877977bbc4f44dd3068b74ee781466c597a3b3
Fixed
204b9645536bb4a77a2cb35e6519dbf9f4ea1665
Type
GIT
Repo
https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git
Events
Introduced
bd3f40fdec552f9200e7b8521ef02b578c9ee8b0
Fixed
00eaa58988d35fd47ca8811f7f72871591f61ffb
Type
GIT
Repo
https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git
Events
Introduced
85a79da286b65ae2238a22ac901a0039779e613e
Fixed
712f3268a62d0df98a7ee991cba963ced2e58007
Type
GIT
Repo
https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git
Events
Introduced
31deaeb11ba7a885116c9c30892b9f763c04d59c
Fixed
d65fe42820b890a6a4644de0a95a812471f79ad3
Fixed
a8803c4f0ac3fa7df5551bbb5a8800c434a94357
Fixed
5828517d17eda27f21d29ea14800c9e0a57bad11
Fixed
badc53620fe813b3a9f727ef9526f98567c2c898

Database specific

source
"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-64321.json"

Linux / Kernel

Package

Name
Kernel

Affected ranges

Type
ECOSYSTEM
Events
Introduced
6.8.0
Fixed
6.12.96
Type
ECOSYSTEM
Events
Introduced
6.13.0
Fixed
6.18.39
Type
ECOSYSTEM
Events
Introduced
6.19.0
Fixed
7.1.4

Database specific

source
"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-64321.json"