Back

MEDIUM

nvme: target: rdma: fix ndev refcount leak on queue connect

Published Jul 25, 2026

Description

nvmet_rdma_queue_connect() calls nvmet_rdma_find_get_device() which acquires a reference on the returned ndev via kref_get(). On the path where the host queue backlog is exceeded and the function returns NVME_SC_CONNECT_CTRL_BUSY, reference of ndev is not released, leaking the kref.

Fix this by adding a goto to the existing put_device label before the early return.

Affected products

Remediation

No remediation recorded yet.

Metrics

Weaknesses (1)

References (12)

Change history (0)

No recorded changes yet.

Sources
CVE.org / MITRE
Status PUBLISHED
Assigner Linux
Published Jul 25, 2026
Updated Sep 14, 2026
Reserved Jul 19, 2026
NVD
Status Modified
Modified Sep 14, 2026
Red Hat
Severity Moderate
Public date Jul 25, 2026