---
id: CVE-2026-90206
title: |-
  In the Linux kernel, the following vulnerability has been resolved:

  nvmet: fix max_qid race between configfs and controller allocation

  The function nvmet_subsys_attr_qid_max_store() can race against
  nvmet_alloc_ctrl() when a subsystem'…
summary: |-
  In the Linux kernel, the following vulnerability has been resolved:

  nvmet: fix max_qid race between configfs and controller allocation

  The function nvmet_subsys_attr_qid_max_store() can race against
  nvmet_alloc_ctrl() when a subsystem'…
severity: none
vendor: Linux
product: Linux
affected:
  - >-
    Linux >= 3e980f5995e0bb4d86fef873a9c9ad66721580d0 <
    2c23fc91789dfd9db746edb3ae9b90d65fabd410
  - >-
    Linux >= 3e980f5995e0bb4d86fef873a9c9ad66721580d0 <
    f1a8846e06388113dfdbb89dee005083fa9afdf9
  - Linux 6.1
published: '2026-09-17'
updated: '2026-09-17'
sourceUpdated: '2026-09-17T17:17:15.700'
source: NVD
sourceUrl: 'https://nvd.nist.gov/vuln/detail/CVE-2026-90206'
references:
  - url: 'https://git.kernel.org/stable/c/2c23fc91789dfd9db746edb3ae9b90d65fabd410'
    label: 416baaa9-dc9f-4396-8d5f-8c081fb06d67
  - url: 'https://git.kernel.org/stable/c/f1a8846e06388113dfdbb89dee005083fa9afdf9'
    label: 416baaa9-dc9f-4396-8d5f-8c081fb06d67
tags:
  - nvd
  - cve.org
ingestedAt: '2026-09-17T16:21:47.859Z'
epss: 0.00198
epssPercentile: 0.08455
---

## Overview

In the Linux kernel, the following vulnerability has been resolved:

nvmet: fix max_qid race between configfs and controller allocation

The function nvmet_subsys_attr_qid_max_store() can race against
nvmet_alloc_ctrl() when a subsystem's max_qid limit is modified.

Suppose max_qid is currently 64. If nvmet_alloc_ctrl() executes:
ctrl->sqs = kzalloc_objs(struct nvmet_sq *, subsys->max_qid + 1);
and at this exact point, a userspace process changes max_qid to 128,
nvmet_subsys_attr_qid_max_store() will set the new max_qid value. It
attempts to delete active controllers to force a reconnect, but the
new controller won't be deleted because it hasn't been added to the
subsys->ctrls list yet.

nvmet_alloc_ctrl() then proceeds and adds the new controller to the
subsys->ctrls list. Later, when nvmet_install_queue() is called, it
will see max_qid set to 128, but the memory allocated for sqs is only
sized for 64 entries. This results in a KASAN out-of-bounds warning
and potential memory corruptions.

Fix this by protecting the queue allocations and list insertion in
nvmet_alloc_ctrl() with down_read(&nvmet_config_sem). Because
nvmet_subsys_attr_qid_max_store() acquires down_write(&nvmet_config_sem)
to modify the attribute, this safely prevents the configfs writer from
modifying max_qid during controller creation.

Copy the max_qid from the subsystem to the controller's structure
during the allocation; ctrl->max_qid never changes as long as the
controller remains in LIVE state, so this will prevent similar race
conditions.

## Remediation

Refer to the linked advisories for vendor-supplied fixes and affected version ranges.
