CVE-2026-46135
In the Linux kernel, the following vulnerability has been resolved:
nvmet-tcp: fix race between ICReq handling and queue teardown
nvmettcphandle_icreq() updates queue->state after sending an
Initialization Connection Response (ICResp), but it does so without
serializing against target-side queue teardown.
If an NVMe/TCP host sends an Initialization Connection Request
(ICReq) and immediately closes the connection, target-side teardown
may start in softirq context before io_work drains the already
buffered ICReq. In that case, nvmettcpschedulereleasequeue()
sets queue->state to NVMETTCPQ_DISCONNECTING and drops the queue
reference under state_lock.
If iowork later processes that ICReq, nvmettcphandleicreq() can
still overwrite the state back to NVMETTCPQ_LIVE. That defeats the
DISCONNECTING-state guard in nvmettcpschedulereleasequeue() and
allows a later socket state change to re-enter teardown and issue a
second kref_put() on an already released queue.
The ICResp send failure path has the same problem. If teardown has
already moved the queue to DISCONNECTING, a send error can still
overwrite the state with NVMETTCPQ_FAILED, again reopening the
window for a second teardown path to drop the queue reference.
Fix this by serializing both post-send state transitions with
state_lock and bailing out if teardown has already started.
Use -ESHUTDOWN as an internal sentinel for that bail-out path rather
than propagating it as a transport error like -ECONNRESET. Keep
nvmettcpsocketerror() setting rcvstate to NVMETTCPRECV_ERR before
honoring that sentinel so receive-side parsing stays quiesced until the
existing release path completes.
Package Versions Affected
Automatically patch vulnerabilities without upgrading
CVSS Version



Related Resources
References
https://git.kernel.org/stable/c/49891c8fe0cb43fbbe480da1cdccfbbaeb820cb3, https://git.kernel.org/stable/c/5293a8882c549fab4a878bc76b0b6c951f980a61, https://git.kernel.org/stable/c/5f0b95ef68ab9afba75b20eebf436130f80c161a, https://git.kernel.org/stable/c/67e1aaf93b495c2f10bc8a5fbba575fbb7f449b6, https://git.kernel.org/stable/c/6f96dea4819d122737b217ea16660d255abbf8c6, https://git.kernel.org/stable/c/9c63cf80895a70eb4fcfcaa725bb1ac9ae76f02b, https://git.kernel.org/stable/c/b7dd4d27aa70bd98bb10572310e913668baf6a65, https://git.kernel.org/stable/c/dcfe4d1f7960e7d1c01642318f3aae1a604f8508, https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/46xxx/CVE-2026-46135.json, https://nvd.nist.gov/vuln/detail/CVE-2026-46135, https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git