Get a Demo

Let's Patch It!

Book a short call with one our specialists, we'll walk you through how Endor Patches work, and ask you a few questions about your environment (like your primary programming languages and repository management). We'll also send you an email right after you fill out the form, feel free to reply with any questions you have in advance!

CVE

DEBIAN-CVE-2026-64535

In the Linux kernel, the following vulnerability has been resolved: nvmet-tcp: Fix potential UAF when ddgst mismatch Shivam Kumar found via vulnerability testing: When data digest is enabled on an N...
Back to all
CVE

DEBIAN-CVE-2026-64535

In the Linux kernel, the following vulnerability has been resolved: nvmet-tcp: Fix potential UAF when ddgst mismatch Shivam Kumar found via vulnerability testing: When data digest is enabled on an N...

In the Linux kernel, the following vulnerability has been resolved:  nvmet-tcp: Fix potential UAF when ddgst mismatch  Shivam Kumar found via vulnerability testing: When data digest is enabled on an NVMe/TCP connection and a digest mismatch occurs on a non-final H2CDATA PDU during an R2T-based data transfer, the digest error handler in nvmettcptryrecvddgst() calls nvmetrequninit() — which performs percpurefput() on the submission queue — but does NOT mark the command as completed. It does not set cqe->status, does not modify rbytesdone, and does not clear any flag. When the subsequent fatal error triggers queue teardown, nvmettcpuninitdataincmds() iterates all commands, checks nvmettcpneeddatain() for each one, and finds that the already-uninited command still appears to need data (because rbytesdone < transferlen and cqe->status == 0). It therefore calls nvmetrequninit() a second time on the same command — a double percpurefput against a single percpuref_get.

Package Versions Affected

Package Version
patch Availability
No items found.

Automatically patch vulnerabilities without upgrading

Fix Without Upgrading
Detect compatible fix
Apply safe remediation
Fix with a single pull request

CVSS Version

Severity
Base Score
CVSS Version
Score Vector
C
H
U
-
C
H
U
0
-
3.1
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
C
H
U
-

Related Resources

No items found.

References

https://security-tracker.debian.org/tracker/CVE-2026-64535

Severity

9.8

CVSS Score
0
10

Basic Information

Base CVSS
9.8
EPSS Probability
0%
EPSS Percentile
0%
Introduced Version
0
Fix Available
6.1.180-1,6.12.100-1,7.1.3-1,6.12.100-1~deb12u1

Fix Critical Vulnerabilities Instantly

Secure your app without upgrading.
Fix Without Upgrading