Use-after-free in Linux kernel - CVE-2026-64534
Published: July 28, 2026
Vulnerability details
The vulnerability allows a remote attacker to cause a denial of service.
The vulnerability exists due to use-after-free in nvmet_tcp_try_recv_ddgst() when processing a command with a data digest mismatch after request initialization previously failed. A remote attacker can send a specially crafted request to cause a denial of service.
The issue can lead to a refcount underflow, kernel warnings, and a permanent workqueue deadlock.
Affected software
Debian Linux
linux (Debian package)
How to mitigate CVE-2026-64534
linux (Debian package) - update to 6.12.100-1
External References
- https://git.kernel.org/stable/c/22ec7a9fe9153d2737ee9b2fa6d2e43a1491decf
- https://git.kernel.org/stable/c/2ed3c9d955e8cd6361f130623baa664a75fb345f
- https://git.kernel.org/stable/c/4606467a75cfc16721937272ed29462a750b60c8
- https://git.kernel.org/stable/c/ba35b1c674ca3841c0dfadd698f2c1b3ec542d4e
- https://git.kernel.org/stable/c/c7874dad84b20433c0fe3919f291a762d40de08b
- https://git.kernel.org/stable/c/d306da8833e75f669d93424fd84940236f3850bc
- https://git.kernel.org/stable/c/e602c93b25bda4a9d0ff1791a4bdbfdcbb074af1