{
  "affected": [
    {
      "ecosystem_specific": {
        "urgency": "not yet assigned"
      },
      "package": {
        "ecosystem": "Debian:12",
        "name": "linux"
      },
      "ranges": [
        {
          "events": [
            {
              "introduced": "0"
            }
          ],
          "type": "ECOSYSTEM"
        }
      ]
    },
    {
      "ecosystem_specific": {
        "urgency": "not yet assigned"
      },
      "package": {
        "ecosystem": "Debian:13",
        "name": "linux"
      },
      "ranges": [
        {
          "events": [
            {
              "introduced": "0"
            },
            {
              "fixed": "6.12.85-1"
            }
          ],
          "type": "ECOSYSTEM"
        }
      ]
    },
    {
      "ecosystem_specific": {
        "urgency": "not yet assigned"
      },
      "package": {
        "ecosystem": "Debian:14",
        "name": "linux"
      },
      "ranges": [
        {
          "events": [
            {
              "introduced": "0"
            },
            {
              "fixed": "6.19.11-1"
            }
          ],
          "type": "ECOSYSTEM"
        }
      ]
    }
  ],
  "details": "In the Linux kernel, the following vulnerability has been resolved:  nvmet: move async event work off nvmet-wq  For target nvmet_ctrl_free() flushes ctrl-\u003easync_event_work. If nvmet_ctrl_free() runs on nvmet-wq, the flush re-enters workqueue completion for the same worker:-  A. Async event work queued on nvmet-wq (prior to disconnect):   nvmet_execute_async_event()      queue_work(nvmet_wq, \u0026ctrl-\u003easync_event_work)    nvmet_add_async_event()      queue_work(nvmet_wq, \u0026ctrl-\u003easync_event_work)  B. Full pre-work chain (RDMA CM path):   nvmet_rdma_cm_handler()      nvmet_rdma_queue_disconnect()        __nvmet_rdma_queue_disconnect()          queue_work(nvmet_wq, \u0026queue-\u003erelease_work)            process_one_work()              lock((wq_completion)nvmet-wq)  \u003c--------- 1st              nvmet_rdma_release_queue_work()  C. Recursive path (same worker):   nvmet_rdma_release_queue_work()      nvmet_rdma_free_queue()        nvmet_sq_destroy()          nvmet_ctrl_put()            nvmet_ctrl_free()              flush_work(\u0026ctrl-\u003easync_event_work)                __flush_work()                  touch_wq_lockdep_map()                  lock((wq_completion)nvmet-wq) \u003c--------- 2nd  Lockdep splat:    ============================================   WARNING: possible recursive locking detected   6.19.0-rc3nvme+ #14 Tainted: G                 N   --------------------------------------------   kworker/u192:42/44933 is trying to acquire lock:   ffff888118a00948 ((wq_completion)nvmet-wq){+.+.}-{0:0}, at: touch_wq_lockdep_map+0x26/0x90    but task is already holding lock:   ffff888118a00948 ((wq_completion)nvmet-wq){+.+.}-{0:0}, at: process_one_work+0x53e/0x660    3 locks held by kworker/u192:42/44933:    #0: ffff888118a00948 ((wq_completion)nvmet-wq){+.+.}-{0:0}, at: process_one_work+0x53e/0x660    #1: ffffc9000e6cbe28 ((work_completion)(\u0026queue-\u003erelease_work)){+.+.}-{0:0}, at: process_one_work+0x1c5/0x660    #2: ffffffff82d4db60 (rcu_read_lock){....}-{1:3}, at: __flush_work+0x62/0x530    Workqueue: nvmet-wq nvmet_rdma_release_queue_work [nvmet_rdma]   Call Trace:    __flush_work+0x268/0x530    nvmet_ctrl_free+0x140/0x310 [nvmet]    nvmet_cq_put+0x74/0x90 [nvmet]    nvmet_rdma_free_queue+0x23/0xe0 [nvmet_rdma]    nvmet_rdma_release_queue_work+0x19/0x50 [nvmet_rdma]    process_one_work+0x206/0x660    worker_thread+0x184/0x320    kthread+0x10c/0x240    ret_from_fork+0x319/0x390  Move async event work to a dedicated nvmet-aen-wq to avoid reentrant flush on nvmet-wq.",
  "id": "DEBIAN-CVE-2026-31557",
  "modified": "2026-09-14T16:47:33.750134442Z",
  "published": "2026-04-24T15:16:30.080Z",
  "references": [
    {
      "type": "ADVISORY",
      "url": "https://security-tracker.debian.org/tracker/CVE-2026-31557"
    }
  ],
  "severity": [
    {
      "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H",
      "type": "CVSS_V3"
    }
  ],
  "upstream": [
    "CVE-2026-31557"
  ]
}