Potential Use-After-Free Vulnerability in Linux Kernel's NVMe/TCP
CVE-2026-64535

Currently unrated

Key Information:

Vendor

Linux

Status
Vendor
CVE Published:
27 July 2026

What is CVE-2026-64535?

A vulnerability in the Linux kernel's NVMe/TCP implementation could lead to a use-after-free condition during data transfer. When a data digest is enabled and a digest mismatch occurs, the error handler fails to complete specific commands properly. This oversight allows subsequent processes to mistakenly attempt further operations on commands that have already been uninitialized, risking stability and security in data handling practices.

Affected Version(s)

Linux 1da177e4c3f41524e886b7f1b8a0c1fc7321cac2 < 96fe2513df590e74b04253a45089cae75569570e

Linux 1da177e4c3f41524e886b7f1b8a0c1fc7321cac2

Linux 1da177e4c3f41524e886b7f1b8a0c1fc7321cac2 < 6f9442983a3e4227afd1c83a5251ddbca585ea21

References

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.