CVE-2026-98056
CVE CVE-2026-98056EUVD EUVD-2026-86709Published 2026-09-25T10:24:02.000ZLast changed 2026-09-25T14:41:59.000ZCVSS 7.5
What the advisory describes
In the Linux kernel, the following vulnerability has been resolved: nvme: remove stale namespaces by NSID range during scan nvme_scan_ns_list() drops the stale namespaces in each gap in the reported NSID list one NSID at a time. Every iteration calls nvme_find_get_ns() to look the namespace up and removes it if it is present. The loop runs once per NSID in the gap rather than once per namespace actually present. NSIDs are 32-bit, so a target with a sparse NSID space can make a single gap spin the loop billions of times with nothing to remove. watchdog: BUG: soft lockup - CPU#4 stuck for 26s! Workqueue: nvme-wq nvme_scan_work [nvme_core] RIP: 0010:__srcu_read_unlock+0xb/0x20 Call Trace: nvme_find_get_ns+0x7d/0xb0 [nvme_core] nvme_scan_ns_list+0xe8/0x280 [nvme_core] nvme_scan_work+0x18a/0x280 [nvme_core] process_one_work+0x197/0x380 worker_thread+0x2fe/0x410 kthread+0xe0/0x100 Rename nvme_remove_invalid_namespaces() to nvme_remove_nsid_range() and give it an open (start, end) NSID range. ctrl->namespaces is sorted by NSID, so the whole gap is dropped in a single walk that stops once end is reached. This bounds the work by the namespaces that are present instead of by the size of the gap.
Source: EUVD (ENISA), in the words of the advisory.
Products the advisory names
These come from the advisory itself, not from any check we performed.
- Linux — Linux 540c801c65eb58e05e0ca38b6fd644a83d7e2b33 <c84ad7407fb16b92d9b7a649cc304a9cf3757897; patch: 6.18.53; 4.5; patch: 7.3-rc2; 540c801c65eb58e05e0ca38b6fd644a83d7e2b33 <f56b2bb4b18b017b056c4c17c66b2c4c54bf6ee4; patch: 0; 540c801c65eb58e05e0ca38b6fd644a83d7e2b33 <4ed7f3d7d435bf5b63da2814dc9270f5ba896011; patch: 6.12.111; 540c801c65eb58e05e0ca38b6fd644a83d7e2b33 <52200fc41a79da430ccf7c126ed837535b087ea2; patch: 7.2.7
The versions shown are the advisory's own. Patchlage compares no version numbers and derives no judgement from them — which version is installed is something a person has to look up.
Carried in the product catalogue
An estate covering these products can be recorded in Patchlage. An advisory about them appears in the next morning's situation report.
- Linux — Linux
Does this concern one of your customers?
This page cannot answer that — it does not know your estate. Whoever has recorded their environments gets the answer the morning after publication, together with a paragraph they can forward to the customer unedited.
Try it for 28 daysPatchlage reports hits and suspected hits. About everything else this system says nothing — neither this page nor the situation report ever claims that an estate is safe.