PatchSiren

PatchSiren cyber security CVE debrief

CVE-2026-98152 Linux CVE debrief

A vulnerability in the Linux kernel's nvmet-rdma component can cause a queue leak when the connect backlog is exceeded, potentially leading to resource exhaustion. This issue has been resolved through kernel updates. The vulnerability affects Linux kernel deployments using the nvmet-rdma component. The connect backlog limit was exceeded, causing a queue leak. This can lead to resource exhaustion and potential system instability. System administrators and kernel maintainers should assess exposure and apply patches.

Vendor
Linux
Product
Unknown
CVSS
Unknown
CISA KEV
Not listed in stored evidence
Original CVE published
2026-09-25
Original CVE updated
2026-09-25
Advisory published
2026-09-25
Advisory updated
2026-09-25

Who should care

Linux system administrators, kernel maintainers, and teams responsible for infrastructure security should assess exposure and apply patches. Affected operators and platforms include Linux kernel deployments using the nvmet-rdma component. Vulnerability management and security teams should review configurations and verify affected scope.

Why it matters

This vulnerability in the Linux kernel's nvmet-rdma component can lead to resource exhaustion and system instability when the connect backlog is exceeded. Linux system administrators and kernel maintainers should assess exposure, apply patches, and review configurations to mitigate potential impacts.

  • Resource exhaustion due to queue leaks
  • Potential system instability or performance degradation
  • Need for kernel updates and configuration review

Technical summary

The Linux kernel's nvmet-rdma component is vulnerable to a queue leak when the connect backlog is exceeded. This can lead to resource exhaustion. The issue has been addressed through kernel updates. The vulnerability affects Linux kernel deployments using the nvmet-rdma component. The connect backlog limit was exceeded, causing a queue leak. This can lead to resource exhaustion and potential system instability. System administrators and kernel maintainers should assess exposure and apply patches. The affected component is nvmet-rdma in the Linux kernel.

Defensive priority

Medium

Recommended defensive actions

  • Review and apply kernel updates to ensure the nvmet-rdma component is patched.
  • Monitor system resources for signs of exhaustion related to nvmet-rdma.
  • Verify backlog limits are appropriately configured for nvmet-rdma.
  • Perform vulnerability scanning to identify potentially affected assets.
  • Review compensating controls for exposed systems while remediation is scheduled and verified.
  • Check relevant monitoring, detection, and logs for exposed assets that need extra review.
  • Track exceptions, retest remediated assets, and close the item only after evidence is documented.

Evidence notes

The CVE record and NVD entry provide details on the vulnerability, but specific exploitation or impact data is not available. The vulnerability was addressed through kernel updates. The affected component is nvmet-rdma in the Linux kernel. The issue is related to queue leaks when the connect backlog is exceeded. Defenders should verify affected scope, apply patches, and review configurations.

Sources and references

Verified primary and authoritative sources

  • CVE-2026-98152 CVE Program record

    Publisher, destination, and source semantics verified

    URL: https://www.cve.org/CVERecord?id=CVE-2026-98152

    CVE Program - Official CVE Program record with source-provided CVE metadata.

  • CVE-2026-98152 NVD vulnerability detail

    Publisher, destination, and source semantics verified

    URL: https://nvd.nist.gov/vuln/detail/CVE-2026-98152

    NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.

Supplemental references

  • Source reference

    Unverified legacy reference

    URL: https://git.kernel.org/stable/c/186414a6a1a34e081b07e8873622f90402346235

    416baaa9-dc9f-4396-8d5f-8c081fb06d67

  • Source reference

    Unverified legacy reference

    URL: https://git.kernel.org/stable/c/287420cde9d6669abcd2878c344db67423eb7df6

    416baaa9-dc9f-4396-8d5f-8c081fb06d67

  • Source reference

    Unverified legacy reference

    URL: https://git.kernel.org/stable/c/32e598324edc3ebb1ac9362d5b9fc30ce0de4873

    416baaa9-dc9f-4396-8d5f-8c081fb06d67

  • Source reference

    Unverified legacy reference

    URL: https://git.kernel.org/stable/c/4f7cf573cdf0ee857448b9b1967d686b07c71e7d

    416baaa9-dc9f-4396-8d5f-8c081fb06d67

  • Source reference

    Unverified legacy reference

    URL: https://git.kernel.org/stable/c/60d56bf0b14d3c545bacb9aeef92a7e6f2cf0caa

    416baaa9-dc9f-4396-8d5f-8c081fb06d67

  • Source reference

    Unverified legacy reference

    URL: https://git.kernel.org/stable/c/e48f9d1076f8c62c3969588d638602b94aaeff12

    416baaa9-dc9f-4396-8d5f-8c081fb06d67

  • Source reference

    Unverified legacy reference

    URL: https://git.kernel.org/stable/c/fb1ed67788e21832b614c23767a088c08cfdd2f2

    416baaa9-dc9f-4396-8d5f-8c081fb06d67

Methodology and review provenance

AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.