Junglewise Threat Intelligence

CVE-2026-64017: Linux Kernel use-after-free in blk-mq cached request handling

CVE-2026-64017 · Severity: info · CVSS 5.5 · Published 2026-07-19

Technologies: Linux Kernel. Vendors: Linux.

Executive brief

A vulnerability was identified in the Linux kernel's block layer, which manages how data is written to and read from storage devices like hard drives and SSDs. Under specific conditions, the system could attempt to use memory that has already been freed, potentially leading to a system crash or instability. This issue primarily affects the reliability and availability of the operating system during heavy storage operations.

Technical details

A use-after-free (UAF) vulnerability exists in the Linux kernel's Multi-Queue Block IO Queueing Mechanism (blk-mq). The flaw occurs during bio submission when a task peeks at a cached request but sleeps before popping it. During this sleep interval, the plug may flush and call blk_mq_free_plug_rqs, which frees the cached requests while they are still being referenced. An attacker could potentially exploit this race condition to cause a kernel panic or denial of service. The fix involves popping the cached request before any potentially blocking calls to ensure the task holds a valid queue reference. Patches have been merged into various stable branches including 6.1.y, 6.6.y, and 7.x.

Affected products

  • Linux Linux Kernel 6.1.72 to 6.2, 6.5.13 to 6.6, 6.6.3 to 6.7, 6.7 to 7.0.11

Timeline

  • 2026-05-21: patched: Initial fix committed to mainline kernel
  • 2026-07-19: disclosed: CVE published to NVD dataset

References

Related threats