Missing Release of Resource after Effective Lifetime in Linux kernel - CVE-2026-64019
Published: July 20, 2026
Linux kernel
Detailed vulnerability description
The vulnerability allows a local user to cause a denial of service.
The vulnerability exists due to improper resource management in the nvme-pci data setup path when handling DMA mapping for PRP, SGL, or metadata descriptors. A local user can trigger data setup errors to cause a denial of service.
The issue occurs when allocation of tracking or descriptor structures fails, or when an invalid bio_vec is detected during PRP mapping.