External risk intelligence

Linux Kernel nvmet-auth Race Condition During Teardown

CVE advisorySeverity: CRITICAL (CVSS 9.8)

CVE-2026-89970

This vulnerability affects Linux kernel NVMe target authentication internals. NVMe over Fabrics (NVMe-oF) targets are typically deployed within internal storage area networks or data center fabrics, not directly exposed to the public internet. Access is restricted to authorized initiators within the private network, making public internet reachability for this specific component very unlikely.

Halo Surface Signal: 1 out of 5 — much less likely to be public-facing.

External exposure likelihood

Horizon Alert

Summary of the vulnerability and why it matters

This Linux kernel vulnerability involves a flaw in how authentication timeouts are handled, potentially allowing a race condition where memory is reused while still being accessed. This could lead to system instability or data corruption if exploited. The primary concern is to confirm if this specific component is active and exposed within your environment.

  • Authentication timeout flaw creates a race condition.
  • Matters if active NVMe target authentication is in use.
  • Confirm relevance and potential exposure.

Attack Path

How an attacker could exploit the issue

An attacker could exploit a race condition in the Linux kernel's NVMe target authentication by triggering a teardown process while related work is still being executed. This could allow an attacker to free or reuse memory that is still being accessed, potentially leading to system compromise.

  • Requires network access.
  • Triggered during transport teardown.
  • Leads to data corruption or access.

Live Threat

Current exploitation, exposure, and threat context

When supported by the advisory, this vulnerability could allow a race condition during storage queue teardown, potentially leading to memory corruption when the authentication work is still running. This could affect the stability and integrity of the Linux kernel's NVMe target authentication services.

  • System memory integrity.
  • Race condition during teardown.
  • Service instability or corruption.

Operational Fix

Recommended remediation, mitigation, and detection steps

This critical vulnerability in the Linux kernel's NVMe target authentication component requires immediate attention from infrastructure and platform teams responsible for storage and networking. The first practical step is to identify all systems running the affected kernel versions, determine their network exposure, and assess their business criticality. Once these systems are inventoried, the accountable owners should be engaged to plan and prioritize remediation efforts based on the assessed risk.

  • Infrastructure and platform teams own resolution.
  • Verify NVMe target exposure and criticality.
  • Synchronize work and plan kernel updates.

Supplementary metadata

Validate whether this threat affects your internet-facing exposure.

Halo Threat Intelligence helps prioritize remediation with Halo Surface Signal and H/A/L/O context. Start exposure validation with a free external attack surface trial.

Frequently asked questions

What is the Linux kernel nvmet-auth component?

It is a subsystem within the Linux kernel responsible for managing authentication for NVMe over Fabrics (NVMe-oF) targets. These targets allow storage devices to be accessed over network connections, such as data center fabrics or internal storage area networks, rather than being directly attached to a single host.

How does the race condition in CVE-2026-89970 work?

The flaw is a synchronization issue during the teardown of a storage queue. Because the system previously failed to wait for background authentication tasks to finish before freeing memory, a race condition occurs where the kernel may try to access memory that has already been deallocated or repurposed, leading to potential instability.

Do I need to trigger a specific action to cause this bug?

Yes. The vulnerability requires triggering a transport teardown—essentially the process of closing or removing an active storage connection—while an authentication timeout task is still running in the background. It is not triggered by typical, stable NVMe data operations.

Is my system at risk according to Halo Surface Signal?

Halo Surface Signal indicates that exploitation is very unlikely because this component is typically deployed within private, internal storage networks. Since these services are rarely exposed to the public internet, they are generally protected from remote attackers.

What should I do first to address this vulnerability?

Start by identifying which of your systems are running Linux kernels that utilize NVMe target authentication. Once inventoried, assess whether those systems are reachable from untrusted networks, and prioritize scheduling a kernel update to apply the necessary synchronization fixes.

References