PatchSiren cyber security CVE debrief
CVE-2026-98154 Linux CVE debrief
A vulnerability in the Linux kernel's nvme-rdma module has been resolved. The vulnerability occurs when the RDMA queue_rq path reports a host path error and then cleans up the command and unmaps the SQE DMA, resulting in double cleanup and DMA unmap after the request is already complete. This issue can cause potential system crashes or instability. Linux kernel administrators and users, particularly those utilizing the nvme-rdma module, should assess their exposure and verify patches or updates to prevent double cleanup and DMA unmap issues. The CVE record and NVD entry provide details on the vulnerability, including its description and CVSS score of 7, classified as HIGH.
- Vendor
- Linux
- Product
- Unknown
- CVSS
- HIGH 7
- CISA KEV
- Not listed in stored evidence
- Original CVE published
- 2026-09-25
- Original CVE updated
- 2026-09-25
- Advisory published
- 2026-09-25
- Advisory updated
- 2026-09-25
Who should care
Linux kernel administrators and users, particularly those utilizing the nvme-rdma module, should assess their exposure and verify patches or updates to prevent double cleanup and DMA unmap issues.
Why it matters
Defenders should prioritize verifying and applying patches for Linux kernel versions affected by this vulnerability, particularly those using the nvme-rdma module, to prevent potential system crashes or instability.
- Potential system crashes or instability due to double cleanup and DMA unmap issues
- Need for verification of Linux kernel versions and patch application to prevent vulnerability exploitation
- Importance of monitoring system logs for error messages related to nvme-rdma
Technical summary
The Linux kernel's nvme-rdma module has a vulnerability that causes double cleanup and DMA unmap after a request is already complete. This occurs when the RDMA queue_rq path reports a host path error and then cleans up the command and unmaps the SQE DMA. The vulnerability has a CVSS score of 7 and is classified as HIGH. Defenders should prioritize verifying and applying patches for Linux kernel versions affected by this vulnerability, particularly those using the nvme-rdma module, to prevent potential system crashes or instability.
Defensive priority
Defenders should prioritize verifying and applying patches for Linux kernel versions affected by this vulnerability, particularly those using the nvme-rdma module.
Recommended defensive actions
- Verify Linux kernel versions in use and check for patches or updates addressing this vulnerability
- Review and update nvme-rdma module configurations to prevent double cleanup and DMA unmap issues
- Monitor system logs for potential error messages related to nvme-rdma
- Perform a thorough review of system configurations and apply patches or updates as necessary
- Conduct regular security audits to identify potential vulnerabilities
- Implement compensating controls for exposed systems while remediation is scheduled and verified
- Track exceptions and retest remediated assets to ensure vulnerability resolution
Evidence notes
The CVE record and NVD entry provide details on the vulnerability, including its description and CVSS score. However, the exact affected Linux kernel versions are not specified in the provided corpus.
Sources and references
Verified primary and authoritative sources
-
CVE-2026-98154 CVE Program record
Publisher, destination, and source semantics verified
URL: https://www.cve.org/CVERecord?id=CVE-2026-98154
CVE Program - Official CVE Program record with source-provided CVE metadata.
-
CVE-2026-98154 NVD vulnerability detail
Publisher, destination, and source semantics verified
URL: https://nvd.nist.gov/vuln/detail/CVE-2026-98154
NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.
Supplemental references
-
Source reference
Unverified legacy reference
URL: https://git.kernel.org/stable/c/171b993a4aed9889159df4815b6a6ba141e61975
416baaa9-dc9f-4396-8d5f-8c081fb06d67
-
Source reference
Unverified legacy reference
URL: https://git.kernel.org/stable/c/a41e7fc8d244d9cfc6273051aed85b67adedbb89
416baaa9-dc9f-4396-8d5f-8c081fb06d67
-
Source reference
Unverified legacy reference
URL: https://git.kernel.org/stable/c/cf3e706963ffbd3ee2568fa0d08ab016f0575ea8
416baaa9-dc9f-4396-8d5f-8c081fb06d67
-
Source reference
Unverified legacy reference
URL: https://git.kernel.org/stable/c/d61828199c6cb4b76d48403c77023cd4bb9d09fc
416baaa9-dc9f-4396-8d5f-8c081fb06d67
Methodology and review provenance
AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.