PatchSiren cyber security CVE debrief
CVE-2026-98152 Linux CVE debrief
A vulnerability in the Linux kernel's nvmet-rdma component can cause a queue leak when the connect backlog is exceeded, potentially leading to resource exhaustion. This issue has been resolved through kernel updates. The vulnerability affects Linux kernel deployments using the nvmet-rdma component. The connect backlog limit was exceeded, causing a queue leak. This can lead to resource exhaustion and potential system instability. System administrators and kernel maintainers should assess exposure and apply patches.
- Vendor
- Linux
- Product
- Unknown
- CVSS
- Unknown
- CISA KEV
- Not listed in stored evidence
- Original CVE published
- 2026-09-25
- Original CVE updated
- 2026-09-25
- Advisory published
- 2026-09-25
- Advisory updated
- 2026-09-25
Who should care
Linux system administrators, kernel maintainers, and teams responsible for infrastructure security should assess exposure and apply patches. Affected operators and platforms include Linux kernel deployments using the nvmet-rdma component. Vulnerability management and security teams should review configurations and verify affected scope.
Why it matters
This vulnerability in the Linux kernel's nvmet-rdma component can lead to resource exhaustion and system instability when the connect backlog is exceeded. Linux system administrators and kernel maintainers should assess exposure, apply patches, and review configurations to mitigate potential impacts.
- Resource exhaustion due to queue leaks
- Potential system instability or performance degradation
- Need for kernel updates and configuration review
Technical summary
The Linux kernel's nvmet-rdma component is vulnerable to a queue leak when the connect backlog is exceeded. This can lead to resource exhaustion. The issue has been addressed through kernel updates. The vulnerability affects Linux kernel deployments using the nvmet-rdma component. The connect backlog limit was exceeded, causing a queue leak. This can lead to resource exhaustion and potential system instability. System administrators and kernel maintainers should assess exposure and apply patches. The affected component is nvmet-rdma in the Linux kernel.
Defensive priority
Medium
Recommended defensive actions
- Review and apply kernel updates to ensure the nvmet-rdma component is patched.
- Monitor system resources for signs of exhaustion related to nvmet-rdma.
- Verify backlog limits are appropriately configured for nvmet-rdma.
- Perform vulnerability scanning to identify potentially affected assets.
- Review compensating controls for exposed systems while remediation is scheduled and verified.
- Check relevant monitoring, detection, and logs for exposed assets that need extra review.
- Track exceptions, retest remediated assets, and close the item only after evidence is documented.
Evidence notes
The CVE record and NVD entry provide details on the vulnerability, but specific exploitation or impact data is not available. The vulnerability was addressed through kernel updates. The affected component is nvmet-rdma in the Linux kernel. The issue is related to queue leaks when the connect backlog is exceeded. Defenders should verify affected scope, apply patches, and review configurations.
Sources and references
Verified primary and authoritative sources
-
CVE-2026-98152 CVE Program record
Publisher, destination, and source semantics verified
URL: https://www.cve.org/CVERecord?id=CVE-2026-98152
CVE Program - Official CVE Program record with source-provided CVE metadata.
-
CVE-2026-98152 NVD vulnerability detail
Publisher, destination, and source semantics verified
URL: https://nvd.nist.gov/vuln/detail/CVE-2026-98152
NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.
Supplemental references
-
Source reference
Unverified legacy reference
URL: https://git.kernel.org/stable/c/186414a6a1a34e081b07e8873622f90402346235
416baaa9-dc9f-4396-8d5f-8c081fb06d67
-
Source reference
Unverified legacy reference
URL: https://git.kernel.org/stable/c/287420cde9d6669abcd2878c344db67423eb7df6
416baaa9-dc9f-4396-8d5f-8c081fb06d67
-
Source reference
Unverified legacy reference
URL: https://git.kernel.org/stable/c/32e598324edc3ebb1ac9362d5b9fc30ce0de4873
416baaa9-dc9f-4396-8d5f-8c081fb06d67
-
Source reference
Unverified legacy reference
URL: https://git.kernel.org/stable/c/4f7cf573cdf0ee857448b9b1967d686b07c71e7d
416baaa9-dc9f-4396-8d5f-8c081fb06d67
-
Source reference
Unverified legacy reference
URL: https://git.kernel.org/stable/c/60d56bf0b14d3c545bacb9aeef92a7e6f2cf0caa
416baaa9-dc9f-4396-8d5f-8c081fb06d67
-
Source reference
Unverified legacy reference
URL: https://git.kernel.org/stable/c/e48f9d1076f8c62c3969588d638602b94aaeff12
416baaa9-dc9f-4396-8d5f-8c081fb06d67
-
Source reference
Unverified legacy reference
URL: https://git.kernel.org/stable/c/fb1ed67788e21832b614c23767a088c08cfdd2f2
416baaa9-dc9f-4396-8d5f-8c081fb06d67
Methodology and review provenance
AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.