Get a Demo

Let's Patch It!

Book a short call with one our specialists, we'll walk you through how Endor Patches work, and ask you a few questions about your environment (like your primary programming languages and repository management). We'll also send you an email right after you fill out the form, feel free to reply with any questions you have in advance!

CVE

CVE-2026-64535

nvmet-tcp: Fix potential UAF when ddgst mismatch
Back to all
CVE

CVE-2026-64535

nvmet-tcp: Fix potential UAF when ddgst mismatch

In the Linux kernel, the following vulnerability has been resolved:

nvmet-tcp: Fix potential UAF when ddgst mismatch

Shivam Kumar found via vulnerability testing:

When data digest is enabled on an NVMe/TCP connection and a digest

mismatch occurs on a non-final H2C_DATA PDU during an R2T-based

data transfer, the digest error handler in nvmettcptryrecvddgst()

calls nvmetrequninit() — which performs percpurefput() on the

submission queue — but does NOT mark the command as completed. It

does not set cqe->status, does not modify rbytes_done, and does not

clear any flag. When the subsequent fatal error triggers queue

teardown, nvmettcpuninitdatain_cmds() iterates all commands,

checks nvmettcpneeddatain() for each one, and finds that the

already-uninited command still appears to need data (because

rbytesdone < transferlen and cqe->status == 0). It therefore calls

nvmetrequninit() a second time on the same command — a double

percpurefput against a single percpurefget.

Package Versions Affected

Package Version
patch Availability
No items found.

Automatically patch vulnerabilities without upgrading

Fix Without Upgrading
Detect compatible fix
Apply safe remediation
Fix with a single pull request

CVSS Version

Severity
Base Score
CVSS Version
Score Vector
C
H
U
9.8
-
3.1
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
C
H
U
0
-
3.1
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
C
H
U
-

Related Resources

No items found.

References

https://git.kernel.org/stable/c/088ee46c18d99baef453afd74181dd40ade044ad, https://git.kernel.org/stable/c/6f9442983a3e4227afd1c83a5251ddbca585ea21, https://git.kernel.org/stable/c/7e558308eba14c8136cb1e615f0c850f76d1fc0a, https://git.kernel.org/stable/c/96fe2513df590e74b04253a45089cae75569570e, https://git.kernel.org/stable/c/dbbd07d0a7020b80f6a7028e561908f7b83b3d5a, https://git.kernel.org/stable/c/dfb902462bca478f050224ec7a7195aafa7643b1, https://git.kernel.org/stable/c/e091ff83d962f9ed00d9bd70443676de9fe98bdc, https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/64xxx/CVE-2026-64535.json, https://nvd.nist.gov/vuln/detail/CVE-2026-64535, https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git

Severity

9.8

CVSS Score
0
10

Basic Information

Base CVSS
9.8
EPSS Probability
0.00547%
EPSS Percentile
0.44562%
Introduced Version
91edfca6f8b364d60cde3ddefaf7d03ddf35774b,fda871c0ba5d2eed2cd1c881573168129da70058,0,5.10.20,5.11.3,5.11.0,5.12.0,5.16.0,6.2.0,6.7.0
Fix Available
dfb902462bca478f050224ec7a7195aafa7643b1,dbbd07d0a7020b80f6a7028e561908f7b83b3d5a,5.10.265,5.12,5.15.216,6.1.178,6.6.145,6.12.97,6.18.40,6.1.180-1,6.12.100-1~deb12u1,6.12.100-1,0:5.15.0-324.217.5.2.el8uek,0:5.15.0-324.217.5.2.el9uek,0:6.12.0-206.104.3.3.el9uek,0:6.12.0-206.104.3.3.el10uek

Fix Critical Vulnerabilities Instantly

Secure your app without upgrading.
Fix Without Upgrading