Use-after-free in Linux kernel - CVE-2026-64534
Published: July 28, 2026
Vulnerability details
The vulnerability allows a remote attacker to cause a denial of service.
The vulnerability exists due to use-after-free in nvmet_tcp_try_recv_ddgst() when processing a command with a data digest mismatch after request initialization previously failed. A remote attacker can send a specially crafted request to cause a denial of service.
The issue can lead to a refcount underflow, kernel warnings, and a permanent workqueue deadlock.
Affected software
Debian Linux
openEuler
kernel
bpftool
bpftool-debuginfo
kernel-debuginfo
kernel-debugsource
kernel-devel
kernel-headers
kernel-source
kernel-tools
kernel-tools-debuginfo
kernel-tools-devel
perf
perf-debuginfo
python3-perf
python3-perf-debuginfo
linux (Debian package)
How to mitigate CVE-2026-64534
kernel - update to 5.10.0-328.0.0.229
bpftool - update to 5.10.0-328.0.0.229
bpftool-debuginfo - update to 5.10.0-328.0.0.229
kernel-debuginfo - update to 5.10.0-328.0.0.229
kernel-debugsource - update to 5.10.0-328.0.0.229
kernel-devel - update to 5.10.0-328.0.0.229
kernel-headers - update to 5.10.0-328.0.0.229
kernel-source - update to 5.10.0-328.0.0.229
kernel-tools - update to 5.10.0-328.0.0.229
kernel-tools-debuginfo - update to 5.10.0-328.0.0.229
kernel-tools-devel - update to 5.10.0-328.0.0.229
perf - update to 5.10.0-328.0.0.229
perf-debuginfo - update to 5.10.0-328.0.0.229
python3-perf - update to 5.10.0-328.0.0.229
python3-perf-debuginfo - update to 5.10.0-328.0.0.229
linux (Debian package) - update to 6.12.100-1
External References
- https://git.kernel.org/stable/c/22ec7a9fe9153d2737ee9b2fa6d2e43a1491decf
- https://git.kernel.org/stable/c/2ed3c9d955e8cd6361f130623baa664a75fb345f
- https://git.kernel.org/stable/c/4606467a75cfc16721937272ed29462a750b60c8
- https://git.kernel.org/stable/c/ba35b1c674ca3841c0dfadd698f2c1b3ec542d4e
- https://git.kernel.org/stable/c/c7874dad84b20433c0fe3919f291a762d40de08b
- https://git.kernel.org/stable/c/d306da8833e75f669d93424fd84940236f3850bc
- https://git.kernel.org/stable/c/e602c93b25bda4a9d0ff1791a4bdbfdcbb074af1