Answer in brief
CVE-2026-64534 records a Critical severity (CVSS 9.8) vulnerability in nvmet-tcp: check INIT_FAILED before nvmet_req_uninit in digest error path. The current sources do not mark it as known exploited. The current feed maps Linux/Linux (generic), Linux/Linux (generic). Check affected ranges and fixed versions before updating.
Analysis pending evidence review
HOL Guard separates source facts from reviewed analysis. See the methodology.
Answer in brief
CVE-2026-64534 records a Critical severity (CVSS 9.8) vulnerability in nvmet-tcp: check INIT_FAILED before nvmet_req_uninit in digest error path. The current sources do not mark it as known exploited. The current feed maps Linux/Linux (generic), Linux/Linux (generic). Check affected ranges and fixed versions before updating.
Analysis pending evidence review
HOL Guard separates source facts from reviewed analysis. See the methodology.
CVSS is 9.8. The current sources do not mark it as known exploited. Treat this as a source-backed prioritization signal, not a statement about your environment.
Analysis status
Analysis pending evidence review
Factual feed record only; HOL analysis is not approved for indexing. Read the methodology.
The current feed maps Linux/Linux (generic), Linux/Linux (generic). Check affected ranges and fixed versions before updating.
| Package | Affected range | Fixed version |
|---|---|---|
| Linux/Linuxgeneric | >=91edfca6f8b364d60cde3ddefaf7d03ddf35774b <22ec7a9fe9153d2737ee9b2fa6d2e43a1491decf || >=fda871c0ba5d2eed2cd1c881573168129da70058 <ba35b1c674ca3841c0dfadd698f2c1b3ec542d4e || >=fda871c0ba5d2eed2cd1c881573168129da70058 <c7874dad84b20433c0fe3919f291a762d40de08b || >=fda871c0ba5d2eed2cd1c881573168129da70058 <e602c93b25bda4a9d0ff1791a4bdbfdcbb074af1 || >=fda871c0ba5d2eed2cd1c881573168129da70058 <d306da8833e75f669d93424fd84940236f3850bc || >=fda871c0ba5d2eed2cd1c881573168129da70058 <2ed3c9d955e8cd6361f130623baa664a75fb345f || >=fda871c0ba5d2eed2cd1c881573168129da70058 <4606467a75cfc16721937272ed29462a750b60c8 || 4b17476d809273617d3317fa0d4ae78aa488d760 || >=5.10.20 <5.10.261 || >=5.11.3 <5.12 | 22ec7a9fe9153d2737ee9b2fa6d2e43a1491decf, ba35b1c674ca3841c0dfadd698f2c1b3ec542d4e, c7874dad84b20433c0fe3919f291a762d40de08b, e602c93b25bda4a9d0ff1791a4bdbfdcbb074af1, d306da8833e75f669d93424fd84940236f3850bc, 2ed3c9d955e8cd6361f130623baa664a75fb345f, 4606467a75cfc16721937272ed29462a750b60c8, 5.10.261, 5.12 |
| Linux/Linuxgeneric | 5.12 | Not reported |
Published upstream
Jul 27, 2026
Evidence: source:cvelist:source_dates:source-dates:recordSource modified
Aug 5, 2026
Evidence: source:cvelist:source_dates:source-dates:recordFirst seen by HOL
Aug 5, 2026
In the Linux kernel, the following vulnerability has been resolved: nvmet-tcp: check INIT_FAILED before nvmet_req_uninit in digest error path In nvmet_tcp_try_recv_ddgst(), when a data digest mismatch is detected, nvmet_req_uninit() is called unconditionally. However, if the command arrived via the nvmet_tcp_handle_req_failure() path, nvmet_req_init() had returned false and percpu_ref_tryget_live() was never executed. The unconditional percpu_ref_put() inside nvmet_req_uninit() then causes a refcount underflow, leading to a WARNING in percpu_ref_switch_to_atomic_rcu, a use-after-free diagnostic, and eventually a permanent workqueue deadlock. Check cmd->flags & NVMET_TCP_F_INIT_FAILED before calling nvmet_req_uninit(), matching the existing pattern in nvmet_tcp_execute_request().
Quoted source text, attributed separately from HOL analysis.
CVSS is 9.8. The current sources do not mark it as known exploited. Treat this as a source-backed prioritization signal, not a statement about your environment.
Analysis status
Analysis pending evidence review
Factual feed record only; HOL analysis is not approved for indexing. Read the methodology.
The current feed maps Linux/Linux (generic), Linux/Linux (generic). Check affected ranges and fixed versions before updating.
| Package | Affected range | Fixed version |
|---|---|---|
| Linux/Linuxgeneric | >=91edfca6f8b364d60cde3ddefaf7d03ddf35774b <22ec7a9fe9153d2737ee9b2fa6d2e43a1491decf || >=fda871c0ba5d2eed2cd1c881573168129da70058 <ba35b1c674ca3841c0dfadd698f2c1b3ec542d4e || >=fda871c0ba5d2eed2cd1c881573168129da70058 <c7874dad84b20433c0fe3919f291a762d40de08b || >=fda871c0ba5d2eed2cd1c881573168129da70058 <e602c93b25bda4a9d0ff1791a4bdbfdcbb074af1 || >=fda871c0ba5d2eed2cd1c881573168129da70058 <d306da8833e75f669d93424fd84940236f3850bc || >=fda871c0ba5d2eed2cd1c881573168129da70058 <2ed3c9d955e8cd6361f130623baa664a75fb345f || >=fda871c0ba5d2eed2cd1c881573168129da70058 <4606467a75cfc16721937272ed29462a750b60c8 || 4b17476d809273617d3317fa0d4ae78aa488d760 || >=5.10.20 <5.10.261 || >=5.11.3 <5.12 | 22ec7a9fe9153d2737ee9b2fa6d2e43a1491decf, ba35b1c674ca3841c0dfadd698f2c1b3ec542d4e, c7874dad84b20433c0fe3919f291a762d40de08b, e602c93b25bda4a9d0ff1791a4bdbfdcbb074af1, d306da8833e75f669d93424fd84940236f3850bc, 2ed3c9d955e8cd6361f130623baa664a75fb345f, 4606467a75cfc16721937272ed29462a750b60c8, 5.10.261, 5.12 |
| Linux/Linuxgeneric | 5.12 | Not reported |
Published upstream
Jul 27, 2026
Evidence: source:cvelist:source_dates:source-dates:recordSource modified
Aug 5, 2026
Evidence: source:cvelist:source_dates:source-dates:recordFirst seen by HOL
Aug 5, 2026
In the Linux kernel, the following vulnerability has been resolved: nvmet-tcp: check INIT_FAILED before nvmet_req_uninit in digest error path In nvmet_tcp_try_recv_ddgst(), when a data digest mismatch is detected, nvmet_req_uninit() is called unconditionally. However, if the command arrived via the nvmet_tcp_handle_req_failure() path, nvmet_req_init() had returned false and percpu_ref_tryget_live() was never executed. The unconditional percpu_ref_put() inside nvmet_req_uninit() then causes a refcount underflow, leading to a WARNING in percpu_ref_switch_to_atomic_rcu, a use-after-free diagnostic, and eventually a permanent workqueue deadlock. Check cmd->flags & NVMET_TCP_F_INIT_FAILED before calling nvmet_req_uninit(), matching the existing pattern in nvmet_tcp_execute_request().
Quoted source text, attributed separately from HOL analysis.