๐Ÿ” CVE Alert

CVE-2026-64534

CRITICAL 9.8

nvmet-tcp: check INIT_FAILED before nvmet_req_uninit in digest error path

CVSS Score
9.8
EPSS Score
0.0%
EPSS Percentile
0th

In the Linux kernel, the following vulnerability has been resolved: nvmet-tcp: check INIT_FAILED before nvmet_req_uninit in digest error path In nvmet_tcp_try_recv_ddgst(), when a data digest mismatch is detected, nvmet_req_uninit() is called unconditionally. However, if the command arrived via the nvmet_tcp_handle_req_failure() path, nvmet_req_init() had returned false and percpu_ref_tryget_live() was never executed. The unconditional percpu_ref_put() inside nvmet_req_uninit() then causes a refcount underflow, leading to a WARNING in percpu_ref_switch_to_atomic_rcu, a use-after-free diagnostic, and eventually a permanent workqueue deadlock. Check cmd->flags & NVMET_TCP_F_INIT_FAILED before calling nvmet_req_uninit(), matching the existing pattern in nvmet_tcp_execute_request().

Vendor linux
Product linux
Ecosystems
Industries
Technology
Published Jul 27, 2026
Last Updated Aug 5, 2026
Stay Ahead of the Next One

Get instant alerts for linux linux

Be the first to know when new critical vulnerabilities affecting linux linux are published โ€” delivered to Slack, Telegram or Discord.

Get Free Alerts โ†’ Free ยท No credit card ยท 60 sec setup

CVSS v3 Breakdown

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Attack Vector
Attack Complexity
Privileges Required
User Interaction
Scope
Confidentiality
Integrity
Availability

Affected Versions

Linux / Linux
91edfca6f8b364d60cde3ddefaf7d03ddf35774b < 22ec7a9fe9153d2737ee9b2fa6d2e43a1491decf fda871c0ba5d2eed2cd1c881573168129da70058 < ba35b1c674ca3841c0dfadd698f2c1b3ec542d4e fda871c0ba5d2eed2cd1c881573168129da70058 < c7874dad84b20433c0fe3919f291a762d40de08b fda871c0ba5d2eed2cd1c881573168129da70058 < e602c93b25bda4a9d0ff1791a4bdbfdcbb074af1 fda871c0ba5d2eed2cd1c881573168129da70058 < d306da8833e75f669d93424fd84940236f3850bc fda871c0ba5d2eed2cd1c881573168129da70058 < 2ed3c9d955e8cd6361f130623baa664a75fb345f fda871c0ba5d2eed2cd1c881573168129da70058 < 4606467a75cfc16721937272ed29462a750b60c8 4b17476d809273617d3317fa0d4ae78aa488d760 5.10.20 < 5.10.261 5.11.3 < 5.12
Linux / Linux
5.12

References

NVD โ†— CVE.org โ†— EPSS Data โ†—
git.kernel.org: https://git.kernel.org/stable/c/22ec7a9fe9153d2737ee9b2fa6d2e43a1491decf git.kernel.org: https://git.kernel.org/stable/c/ba35b1c674ca3841c0dfadd698f2c1b3ec542d4e git.kernel.org: https://git.kernel.org/stable/c/c7874dad84b20433c0fe3919f291a762d40de08b git.kernel.org: https://git.kernel.org/stable/c/e602c93b25bda4a9d0ff1791a4bdbfdcbb074af1 git.kernel.org: https://git.kernel.org/stable/c/d306da8833e75f669d93424fd84940236f3850bc git.kernel.org: https://git.kernel.org/stable/c/2ed3c9d955e8cd6361f130623baa664a75fb345f git.kernel.org: https://git.kernel.org/stable/c/4606467a75cfc16721937272ed29462a750b60c8