Use-after-free in Linux kernel - CVE-2026-64535
Published: July 28, 2026
Vulnerability details
The vulnerability allows a remote user to cause a denial of service.
The vulnerability exists due to a use-after-free in the NVMe/TCP target digest error handling in nvmet_tcp_try_recv_ddgst() and queue teardown logic when processing a digest mismatch on a non-final H2C_DATA PDU during an R2T-based data transfer. A remote user can trigger a digest mismatch to cause a denial of service.
Exploitation requires data digest to be enabled on the NVMe/TCP connection.
Affected software
Debian Linux
linux (Debian package)
How to mitigate CVE-2026-64535
linux (Debian package) - update to 6.12.100-1
External References
- https://git.kernel.org/stable/c/088ee46c18d99baef453afd74181dd40ade044ad
- https://git.kernel.org/stable/c/6f9442983a3e4227afd1c83a5251ddbca585ea21
- https://git.kernel.org/stable/c/96fe2513df590e74b04253a45089cae75569570e
- https://git.kernel.org/stable/c/dbbd07d0a7020b80f6a7028e561908f7b83b3d5a
- https://git.kernel.org/stable/c/e091ff83d962f9ed00d9bd70443676de9fe98bdc