Review reviewHigh

CVE-2026-64017

Linux

In the Linux kernel, the following vulnerability has been resolved: blk-mq: pop cached request if it is usable When submitting a bio to blk-mq, if the task should sleep after peeking a cached request, but before it pops it, the plug flushes and calls blk_mq_free_plug_rqs, freeing the cached_rqs. This creates a use-after-free bug. Fix this by popping the cached request before any possible blocking calls if it is suitable for use. Popping this request first holds a queue reference, so avoid any serialization races with queue freezes and can safely proceed with dispatching that request to the...

CVSS
7.8
EPSS
-
- percentile
CISA KEV
Not listed
Published
2026.07.20
PRIORITY ASSESSMENT

Review review

The CVSS severity warrants an early asset and exposure review.

Known exploitationNot established by KEV
Exploit probability-
Technical severityCVSS 7.8

Vulnerability overview

In the Linux kernel, the following vulnerability has been resolved: blk-mq: pop cached request if it is usable When submitting a bio to blk-mq, if the task should sleep after peeking a cached request, but before it pops it, the plug flushes and calls blk_mq_free_plug_rqs, freeing the cached_rqs. This creates a use-after-free bug. Fix this by popping the cached request before any possible blocking calls if it is suitable for use. Popping this request first holds a queue reference, so avoid any serialization races with queue freezes and can safely proceed with dispatching that request to the...

Affected product and versions

Product
Linux
Affected versions
>= b0077e269f6c152e807fdac90b58caf012cdbaab < 388468f7e7d1eab092cf2a39fdfb502e52019ec6, >= b0077e269f6c152e807fdac90b58caf012cdbaab < dc278e9bf2b9513a763353e6b9cc21e0f532954e, >= b5c8e0ff76d10f6bf70a7237678f27c20cf59bc9, >= e9c309ded295b7f8849097d71ae231456ca79f78, >= b80056bd75a16e4550873ecefe12bc8fd190b1cf, >= 33cf52b6e53a6aa55883aa7fb9ceffceff8488a6, >= 8b6075046470c8756242dfe3fd058813636f69a3, >= 6.1.72 < 6.2, >= 6.5.13 < 6.6, >= 6.6.3 < 6.7, >= 6.1.75 < 6.2, >= 6.6.14 < 6.7, >= 6.7
Fixed versions
No verified fixed-version field is available yet

Recommended response sequence

Confirm exposure before applying a vendor-supported change.

Full remediation guide
  1. 1
    Identify

    Confirm that Linux and an affected version are present.

  2. 2
    Prioritize

    Combine exploitation signals with asset exposure and business criticality.

  3. 3
    Remediate

    Follow the vendor advisory or supported update path and preserve rollback options.

  4. 4
    Verify

    Recheck the version, service health, access paths, and relevant logs.

Technical data

CVSS vector
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
CWE
Not available