Linux Kernel Vulnerability in nvmet-tcp for Multiple Vendors
CVE-2026-64534

Currently unrated

Key Information:

Vendor

Linux

Status
Vendor
CVE Published:
27 July 2026

What is CVE-2026-64534?

A vulnerability exists in the Linux kernel's nvmet-tcp subsystem related to improper handling of data digest mismatches. When a data digest discrepancy occurs, the system calls nvmet_req_uninit() without verifying whether the command initiated encountered a failure. This oversight can lead to a reference count underflow, triggering a WARNING during the refcount management process and risks a potential use-after-free condition. This could culminate in a deadlock situation in the workqueue, severely affecting system stability and performance.

Affected Version(s)

Linux 1da177e4c3f41524e886b7f1b8a0c1fc7321cac2 < 22ec7a9fe9153d2737ee9b2fa6d2e43a1491decf

Linux 1da177e4c3f41524e886b7f1b8a0c1fc7321cac2

Linux 1da177e4c3f41524e886b7f1b8a0c1fc7321cac2

References

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.