{"id":"CVE-2026-98154","title":"In the Linux kernel, the following vulnerability has been resolved:\n\nnvme-rdma: fix -EIO cleanup order in queue_rq\n\nOn -EIO, the RDMA queue_rq path reports a host path error and then\nstill cleans up the command and unmaps the SQE DMA","summary":"In the Linux kernel, the following vulnerability has been resolved:\n\nnvme-rdma: fix -EIO cleanup order in queue_rq\n\nOn -EIO, the RDMA queue_rq path reports a host path error and then\nstill cleans up the command and unmaps the SQE DMA. Th…","severity":"high","cvss":7,"cvssVector":"CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H","vendor":"Linux","product":"Linux","affected":["Linux >= 62eca39722fd997e3621fc903229917b9f0fb271 < a41e7fc8d244d9cfc6273051aed85b67adedbb89","Linux >= 62eca39722fd997e3621fc903229917b9f0fb271 < cf3e706963ffbd3ee2568fa0d08ab016f0575ea8","Linux >= 62eca39722fd997e3621fc903229917b9f0fb271 < 171b993a4aed9889159df4815b6a6ba141e61975","Linux >= 62eca39722fd997e3621fc903229917b9f0fb271 < d61828199c6cb4b76d48403c77023cd4bb9d09fc","Linux 5.12"],"published":"2026-09-25","updated":"2026-09-25","sourceUpdated":"2026-09-25T15:18:07.120","source":"NVD","sourceUrl":"https://nvd.nist.gov/vuln/detail/CVE-2026-98154","references":[{"url":"https://git.kernel.org/stable/c/171b993a4aed9889159df4815b6a6ba141e61975","label":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/a41e7fc8d244d9cfc6273051aed85b67adedbb89","label":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/cf3e706963ffbd3ee2568fa0d08ab016f0575ea8","label":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/d61828199c6cb4b76d48403c77023cd4bb9d09fc","label":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"}],"tags":["nvd","cve.org"],"ingestedAt":"2026-09-25T11:06:38.804Z","slug":"CVE-2026-98154","body":"## Overview\n\nIn the Linux kernel, the following vulnerability has been resolved:\n\nnvme-rdma: fix -EIO cleanup order in queue_rq\n\nOn -EIO, the RDMA queue_rq path reports a host path error and then\nstill cleans up the command and unmaps the SQE DMA. The path error\nhelper completes the request, so that is double cleanup and DMA unmap\nafter the request is already complete.\n\nUnmap the SQE first, then report the host path error. Skip the outer\ncommand cleanup on that path.\n\n## Remediation\n\nRefer to the linked advisories for vendor-supplied fixes and affected version ranges.","depth":"twilight","depthScore":39,"depthScoreParts":{"impact":38.5,"likelihood":0,"exploitation":0,"ransomware":0},"changes":[{"seq":210890,"id":"CVE-2026-98154","ts":1790349113203,"field":"cvss","old":null,"new":"7"},{"seq":210889,"id":"CVE-2026-98154","ts":1790349113203,"field":"severity","old":"none","new":"high"}]}