CVE-2026-64535
Last modified
CVE-2026-64535 is a critical-severity vulnerability rated 9.8/10 on the CVSS scale. In the Linux kernel, the following vulnerability has been resolved: nvmet-tcp: Fix potential UAF when ddgst mismatch Shivam Kumar found via vulnerability testing: When data digest is enabled on an NVMe/TCP connection and a digest mismatch occurs on a non-final H2C_DATA PDU during an R2T-based data transfer, the digest error handler in nvmet_tcp_try_recv_ddgst() calls nvmet_req_uninit() — which performs percpu_ref_put() on the submission queue — but does NOT mark the command as completed. It does not set cqe->status, does not modify rbytes_done, and does not clear any flag. EPSS estimates a 0.47% chance of exploitation in the next 30 days.
Description
In the Linux kernel, the following vulnerability has been resolved: nvmet-tcp: Fix potential UAF when ddgst mismatch Shivam Kumar found via vulnerability testing: When data digest is enabled on an NVMe/TCP connection and a digest mismatch occurs on a non-final H2C_DATA PDU during an R2T-based data transfer, the digest error handler in nvmet_tcp_try_recv_ddgst() calls nvmet_req_uninit() — which performs percpu_ref_put() on the submission queue — but does NOT mark the command as completed. It does not set cqe->status, does not modify rbytes_done, and does not clear any flag. When the subsequent fatal error triggers queue teardown, nvmet_tcp_uninit_data_in_cmds() iterates all commands, checks nvmet_tcp_need_data_in() for each one, and finds that the already-uninited command still appears to need data (because rbytes_done < transfer_len and cqe->status == 0). It therefore calls nvmet_req_uninit() a second time on the same command — a double percpu_ref_put against a single percpu_ref_get.
Metrics
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Affected Software
Source: CNA advisory (CVE.org). NVD analysis pending.
| Vendor | Product | Versions |
|---|---|---|
| Linux | Linux | >= fda871c0ba5d2eed2cd1c881573168129da70058, < 96fe2513df590e74b04253a45089cae75569570e; >= fda871c0ba5d2eed2cd1c881573168129da70058, < e091ff83d962f9ed00d9bd70443676de9fe98bdc; >= fda871c0ba5d2eed2cd1c881573168129da70058, < 6f9442983a3e4227afd1c83a5251ddbca585ea21; >= fda871c0ba5d2eed2cd1c881573168129da70058, < 088ee46c18d99baef453afd74181dd40ade044ad; >= fda871c0ba5d2eed2cd1c881573168129da70058, < dbbd07d0a7020b80f6a7028e561908f7b83b3d5a; 91edfca6f8b364d60cde3ddefaf7d03ddf35774b; 4b17476d809273617d3317fa0d4ae78aa488d760; >= 5.10.20, < 5.11; >= 5.11.3, < 5.12 |
| Linux | Linux | 5.12 |
References
Timeline
- Published
- Last Modified
- Status
- Received
Frequently Asked Questions
What is CVE-2026-64535?
How severe is CVE-2026-64535?
How do I fix CVE-2026-64535?
How Strix Helps
- How Strix found a critical auth bypass in etcdStrix autonomously discovered a critical authentication bypass in etcd, later designated CVE-2026-33413.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2026
- CVE-2026-6453The CubeWP Framework plugin for WordPress is vulnerable to S…6.5
- CVE-2026-64530In the Linux kernel, the following vulnerability has been re…9.8
- CVE-2026-64531In the Linux kernel, the following vulnerability has been re…7.8
- CVE-2026-64532In the Linux kernel, the following vulnerability has been re…7.8
- CVE-2026-64533In the Linux kernel, the following vulnerability has been re…7.8
- CVE-2026-64534In the Linux kernel, the following vulnerability has been re…9.8
- CVE-2026-64536In the Linux kernel, the following vulnerability has been re…8.1
- CVE-2026-64537In the Linux kernel, the following vulnerability has been re…
- CVE-2026-64538In the Linux kernel, the following vulnerability has been re…
- CVE-2026-64539In the Linux kernel, the following vulnerability has been re…7.8
- CVE-2026-6454The Firelight Lightbox plugin for WordPress is vulnerable to…6.4
- CVE-2026-64540In the Linux kernel, the following vulnerability has been re…8.1
Are you affected by CVE-2026-64535?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
