Review reviewCritical

CVE-2026-64534

Linux

In the Linux kernel, the following vulnerability has been resolved: nvmet-tcp: check INIT_FAILED before nvmet_req_uninit in digest error path In nvmet_tcp_try_recv_ddgst(), when a data digest mismatch is detected, nvmet_req_uninit() is called unconditionally. However, if the command arrived via the nvmet_tcp_handle_req_failure() path, nvmet_req_init() had returned false and percpu_ref_tryget_live() was never executed. The unconditional percpu_ref_put() inside nvmet_req_uninit() then causes a refcount underflow, leading to a WARNING in percpu_ref_switch_to_atomic_rcu, a use-after-free diagno...

CVSS
9.8
EPSS
-
- percentile
CISA KEV
Not listed
Published
2026.07.27
PRIORITY ASSESSMENT

Review review

The CVSS severity warrants an early asset and exposure review.

Known exploitationNot established by KEV
Exploit probability-
Technical severityCVSS 9.8

Vulnerability overview

In the Linux kernel, the following vulnerability has been resolved: nvmet-tcp: check INIT_FAILED before nvmet_req_uninit in digest error path In nvmet_tcp_try_recv_ddgst(), when a data digest mismatch is detected, nvmet_req_uninit() is called unconditionally. However, if the command arrived via the nvmet_tcp_handle_req_failure() path, nvmet_req_init() had returned false and percpu_ref_tryget_live() was never executed. The unconditional percpu_ref_put() inside nvmet_req_uninit() then causes a refcount underflow, leading to a WARNING in percpu_ref_switch_to_atomic_rcu, a use-after-free diagno...

Affected product and versions

Product
Linux
Affected versions
>= 1da177e4c3f41524e886b7f1b8a0c1fc7321cac2 < 22ec7a9fe9153d2737ee9b2fa6d2e43a1491decf, >= 1da177e4c3f41524e886b7f1b8a0c1fc7321cac2 < ba35b1c674ca3841c0dfadd698f2c1b3ec542d4e, >= 1da177e4c3f41524e886b7f1b8a0c1fc7321cac2 < c7874dad84b20433c0fe3919f291a762d40de08b, >= 1da177e4c3f41524e886b7f1b8a0c1fc7321cac2 < e602c93b25bda4a9d0ff1791a4bdbfdcbb074af1, >= 1da177e4c3f41524e886b7f1b8a0c1fc7321cac2 < d306da8833e75f669d93424fd84940236f3850bc, >= 1da177e4c3f41524e886b7f1b8a0c1fc7321cac2 < 2ed3c9d955e8cd6361f130623baa664a75fb345f, >= 1da177e4c3f41524e886b7f1b8a0c1fc7321cac2 < 4606467a75cfc16721937272ed29462a750b60c8, < 5.10.261, < 5.15.212, < 6.1.178, < 6.6.145, < 6.12.97, < 6.18.40
Fixed versions
No verified fixed-version field is available yet

Recommended response sequence

Confirm exposure before applying a vendor-supported change.

Full remediation guide
  1. 1
    Identify

    Confirm that Linux and an affected version are present.

  2. 2
    Prioritize

    Combine exploitation signals with asset exposure and business criticality.

  3. 3
    Remediate

    Follow the vendor advisory or supported update path and preserve rollback options.

  4. 4
    Verify

    Recheck the version, service health, access paths, and relevant logs.

Technical data

CVSS vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
CWE
Not available