CVE-2024-41082

MEDIUM

Linux Kernel < 6.9.11 - Denial of Service via NVMe Fabrics Tag Exhaustion

Title source: llm
STIX 2.1

Description

In the Linux kernel, the following vulnerability has been resolved: nvme-fabrics: use reserved tag for reg read/write command In some scenarios, if too many commands are issued by nvme command in the same time by user tasks, this may exhaust all tags of admin_q. If a reset (nvme reset or IO timeout) occurs before these commands finish, reconnect routine may fail to update nvme regs due to insufficient tags, which will cause kernel hang forever. In order to workaround this issue, maybe we can let reg_read32()/reg_read64()/reg_write32() use reserved tags. This maybe safe for nvmf: 1. For the disable ctrl path, we will not issue connect command 2. For the enable ctrl / fw activate path, since connect and reg_xx() are called serially. So the reserved tags may still be enough while reg_xx() use reserved tags.

Scores

CVSS v3 5.5
EPSS 0.0023
EPSS Percentile 13.4%
Attack Vector LOCAL
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H

CISA SSVC

Vulnrichment
Exploitation none
Automatable no
Technical Impact partial

Details

Status published
Products (9)
linux/Kernel 5.4.0 - 6.9.11linux
Linux/Linux < 5.4
Linux/Linux 5.4
Linux/Linux 6.10
Linux/Linux 6.9.11 - 6.9.*
Linux/Linux e7832cb48a654cd12b2bc9181b2f0ad49d526ac6 - 165da9c67a26f08c9b956c15d701da7690f45bcb
Linux/Linux e7832cb48a654cd12b2bc9181b2f0ad49d526ac6 - 7dc3bfcb4c9cc58970fff6aaa48172cb224d85aa
linux/linux_kernel 6.10 rc1 (2 CPE variants)
linux/linux_kernel < 6.9.11
Published Jul 29, 2024
Tracked Since Feb 18, 2026