{
  "affected": [
    {
      "ecosystem_specific": {
        "urgency": "not yet assigned"
      },
      "package": {
        "ecosystem": "Debian:12",
        "name": "linux"
      },
      "ranges": [
        {
          "events": [
            {
              "introduced": "0"
            }
          ],
          "type": "ECOSYSTEM"
        }
      ]
    },
    {
      "ecosystem_specific": {
        "urgency": "not yet assigned"
      },
      "package": {
        "ecosystem": "Debian:13",
        "name": "linux"
      },
      "ranges": [
        {
          "events": [
            {
              "introduced": "0"
            },
            {
              "fixed": "6.12.111-1"
            }
          ],
          "type": "ECOSYSTEM"
        }
      ]
    },
    {
      "ecosystem_specific": {
        "urgency": "not yet assigned"
      },
      "package": {
        "ecosystem": "Debian:14",
        "name": "linux"
      },
      "ranges": [
        {
          "events": [
            {
              "introduced": "0"
            },
            {
              "fixed": "7.2.6-1"
            }
          ],
          "type": "ECOSYSTEM"
        }
      ]
    }
  ],
  "details": "In the Linux kernel, the following vulnerability has been resolved:  nvme-fc: Do not cancel requests in io target before it is initialized  A new nvme-fc controller in CONNECTING state sees admin request timeout schedules ctrl-\u003eioerr_work to abort inflight requests. This ends up calling __nvme_fc_abort_outstanding_ios() which aborts requests in both admin and io tagsets. In case fc_ctrl-\u003etag_set was not initialized we see the warning below. This is because ctrl.queue_count is initialized early in nvme_fc_alloc_ctrl().  nvme nvme0: NVME-FC{0}: starting error recovery Connectivity Loss INFO: trying to register non-static key. The code is fine but needs lockdep annotation, or maybe lpfc 0000:ab:00.0: queue 0 connect admin queue failed (-6). you didn't initialize this object before use? turning off the locking correctness validator. Workqueue: nvme-reset-wq nvme_fc_ctrl_ioerr_work [nvme_fc] Call Trace:  \u003cTASK\u003e  dump_stack_lvl+0x57/0x80  register_lock_class+0x567/0x580  __lock_acquire+0x330/0xb90  lock_acquire.part.0+0xad/0x210  blk_mq_tagset_busy_iter+0xf9/0xc00  __nvme_fc_abort_outstanding_ios+0x23f/0x320 [nvme_fc]  nvme_fc_ctrl_ioerr_work+0x172/0x210 [nvme_fc]  process_one_work+0x82c/0x1450  worker_thread+0x5ee/0xfd0  kthread+0x3a0/0x750  ret_from_fork+0x439/0x670  ret_from_fork_asm+0x1a/0x30  \u003c/TASK\u003e  Update the check in __nvme_fc_abort_outstanding_ios() confirm that io tagset was created before iterating over busy requests. Also make sure to cancel ctrl-\u003eioerr_work before removing io tagset.",
  "id": "DEBIAN-CVE-2026-97409",
  "modified": "2026-09-29T10:47:31.116256260Z",
  "published": "2026-09-24T17:17:18.463Z",
  "references": [
    {
      "type": "ADVISORY",
      "url": "https://security-tracker.debian.org/tracker/CVE-2026-97409"
    }
  ],
  "severity": [
    {
      "score": "CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H",
      "type": "CVSS_V3"
    }
  ],
  "upstream": [
    "CVE-2026-97409"
  ]
}