Junglewise Threat Intelligence

CVE-2026-64535: Linux Kernel use-after-free in nvmet-tcp during digest mismatch

CVE-2026-64535 · Severity: info · CVSS 0 · Published 2026-07-27

Technologies: Linux Kernel. Vendors: Linux.

Executive brief

A vulnerability was identified in the Linux kernel's NVMe-over-TCP implementation, which is used for high-performance network storage. When data verification (digests) is enabled, a specific type of network error can cause the system to incorrectly release memory resources twice. This could lead to a system crash or potentially allow an attacker to disrupt storage services.

Technical details

A use-after-free (UAF) vulnerability exists in the Linux kernel's nvmet-tcp driver. When data digest is enabled and a mismatch occurs on a non-final H2C_DATA PDU during an R2T-based transfer, the error handler `nvmet_tcp_try_recv_ddgst()` calls `nvmet_req_uninit()` without marking the command as completed. During subsequent queue teardown, `nvmet_tcp_uninit_data_in_cmds()` finds the command still active and calls `nvmet_req_uninit()` again, resulting in a double `percpu_ref_put()`. This can lead to premature memory reclamation and subsequent use-after-free. The issue is resolved by ensuring the command status is set to `NVME_SC_CMD_SEQ_ERROR` during the initial error handling.

Affected products

  • Linux Linux Kernel 6.1.178, 6.6.145, 6.12.97, 6.18.40

Timeline

  • 2026-07-27: disclosed
  • 2026-07-27: advisory

References

Related threats