CVE Wiki Pixee · CVE intelligence
← All CVEs

CVE-2026-64534

Critical · CVSS 9.8
CVSS
9.8
nvd
EPSS
KEV
No
Class
oss containerizable

Description

In the Linux kernel, the following vulnerability has been resolved: nvmet-tcp: check INIT_FAILED before nvmet_req_uninit in digest error path In nvmet_tcp_try_recv_ddgst(), when a data digest mismatch is detected, nvmet_req_uninit() is called unconditionally. However, if the command arrived via the nvmet_tcp_handle_req_failure() path, nvmet_req_init() had returned false and percpu_ref_tryget_live() was never executed. The unconditional percpu_ref_put() inside nvmet_req_uninit() then causes a refcount underflow, leading to a WARNING in percpu_ref_switch_to_atomic_rcu, a use-after-free diagnostic, and eventually a permanent workqueue deadlock. Check cmd->flags & NVMET_TCP_F_INIT_FAILED before calling nvmet_req_uninit(), matching the existing pattern in nvmet_tcp_execute_request().

Affected packages

Linux Kernel 0 → 5.10.261
Linux Kernel 5.11.0 → 5.15.212
Linux Kernel 5.16.0 → 6.1.178
Linux Kernel 6.13.0 → 6.18.40
Linux Kernel 6.2.0 → 6.6.145
Linux Kernel 6.7.0 → 6.12.97

References

Status: profiled · ingested 2026-07-30T12:00:00.000Z