Linux Kernel NVMe PCI DMA Mapping Leak Vulnerability

Vulnerability

A vulnerability in the Linux kernel's NVMe over PCI driver can lead to a DMA mapping leak. This issue occurs when the driver fails to allocate a tracking descriptor for both Partial Request Pages (PRP) and Scatter-Gather Lists (SGL), causing the initial DMA mapping to leak during iteration. The problem also arises when the driver encounters an invalid bio_vec while mapping PRPs. The vulnerability affects the stable versions of the Linux kernel.

Impact

The vulnerability can cause a memory leak by failing to properly unmap DMA resources, potentially leading to increased memory usage and degradation of system performance.

Remediation

Users can upgrade to the latest stable version of the Linux kernel to address this vulnerability.

Added: Jul 19, 2026, 6:40 PM
Updated: Jul 19, 2026, 6:40 PM

Vulnerability Rating

Custom Algorithm
spread
9.0
impact
0.6
exploitability
4.0
remediation
7.7
relevance
9.7
threat
3.2
urgency
2.9
incentive
0.0

Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.