Junglewise Threat Intelligence

CVE-2026-64072: Linux Kernel NVMe bio leak in ioctl mapping failure

CVE-2026-64072 · Severity: info · CVSS 0 · Published 2026-07-19

Technologies: Linux Kernel. Vendors: Linux.

Executive brief

A vulnerability in the Linux kernel's NVMe driver could lead to a memory leak when handling storage requests. This occurs when the system fails to properly map data integrity information, causing internal memory structures to remain allocated even after an error. Over time, this could potentially impact system performance or stability by exhausting available memory.

Technical details

A vulnerability in the Linux kernel NVMe driver's ioctl component (drivers/nvme/host/ioctl.c) results in a bio structure leak. In the nvme_map_user_request function, a local bio pointer was initialized to NULL and never updated, causing the cleanup routine (out_unmap) to skip unmapping the bio if an integrity mapping failure occurred. An attacker with local access could potentially trigger this leak by repeatedly providing malformed or incompatible integrity metadata in NVMe ioctl requests. The fix involves correctly referencing the bio directly from the request structure during the unmap phase. Patches have been applied to various stable branches including 6.18.34 and 7.0.11.

Affected products

  • Linux Linux Kernel 6.18, 7.0, 7.1

Timeline

  • 2026-05-06: other: Patch authored
  • 2026-07-19: disclosed: CVE published

References

Related threats