Answer in brief
CVE-2026-98056 records a High severity (CVSS 7.5) vulnerability in nvme: remove stale namespaces by NSID range during scan. The current sources do not mark it as known exploited. The current feed maps Linux/Linux (generic), Linux/Linux (generic). Check affected ranges and fixed versions before updating.
Analysis pending evidence review
HOL Guard separates source facts from reviewed analysis. See the methodology.
CVSS is 7.5. The current sources do not mark it as known exploited. Treat this as a source-backed prioritization signal, not a statement about your environment.
Analysis status
Analysis pending evidence review
Factual feed record only; HOL analysis is not approved for indexing. Read the methodology.
The current feed maps Linux/Linux (generic), Linux/Linux (generic). Check affected ranges and fixed versions before updating.
| Package | Affected range | Fixed version |
|---|---|---|
| Linux/Linuxgeneric | >=540c801c65eb58e05e0ca38b6fd644a83d7e2b33 <c84ad7407fb16b92d9b7a649cc304a9cf3757897 || >=540c801c65eb58e05e0ca38b6fd644a83d7e2b33 <f56b2bb4b18b017b056c4c17c66b2c4c54bf6ee4 || >=540c801c65eb58e05e0ca38b6fd644a83d7e2b33 <52200fc41a79da430ccf7c126ed837535b087ea2 || >=540c801c65eb58e05e0ca38b6fd644a83d7e2b33 <4ed7f3d7d435bf5b63da2814dc9270f5ba896011 | c84ad7407fb16b92d9b7a649cc304a9cf3757897, f56b2bb4b18b017b056c4c17c66b2c4c54bf6ee4, 52200fc41a79da430ccf7c126ed837535b087ea2, 4ed7f3d7d435bf5b63da2814dc9270f5ba896011 |
| Linux/Linuxgeneric | 4.5 | Not reported |
Published upstream
Sep 25, 2026
Evidence: source:cvelist:source_dates:source-dates:recordSource modified
Sep 25, 2026
Evidence: source:cvelist:source_dates:source-dates:recordFirst seen by HOL
Sep 25, 2026
In the Linux kernel, the following vulnerability has been resolved: nvme: remove stale namespaces by NSID range during scan nvme_scan_ns_list() drops the stale namespaces in each gap in the reported NSID list one NSID at a time. Every iteration calls nvme_find_get_ns() to look the namespace up and removes it if it is present. The loop runs once per NSID in the gap rather than once per namespace actually present. NSIDs are 32-bit, so a target with a sparse NSID space can make a single gap spin the loop billions of times with nothing to remove. watchdog: BUG: soft lockup - CPU#4 stuck for 26s! Workqueue: nvme-wq nvme_scan_work [nvme_core] RIP: 0010:__srcu_read_unlock+0xb/0x20 Call Trace: nvme_find_get_ns+0x7d/0xb0 [nvme_core] nvme_scan_ns_list+0xe8/0x280 [nvme_core] nvme_scan_work+0x18a/0x280 [nvme_core] process_one_work+0x197/0x380 worker_thread+0x2fe/0x410 kthread+0xe0/0x100 Rename nvme_remove_invalid_namespaces() to nvme_remove_nsid_range() and give it an open (start, end) NSID range. ctrl->namespaces is sorted by NSID, so the whole gap is dropped in a single walk that stops once end is reached. This bounds the work by the namespaces that are present instead of by the size of the gap.
Quoted source text, attributed separately from HOL analysis.