CVE-2026-64534 PUBLISHED

nvmet-tcp: check INIT_FAILED before nvmet_req_uninit in digest error path

Assigner: Linux
Reserved: 19.07.2026 Published: 27.07.2026 Updated: 27.07.2026

In the Linux kernel, the following vulnerability has been resolved:

nvmet-tcp: check INIT_FAILED before nvmet_req_uninit in digest error path

In nvmet_tcp_try_recv_ddgst(), when a data digest mismatch is detected, nvmet_req_uninit() is called unconditionally. However, if the command arrived via the nvmet_tcp_handle_req_failure() path, nvmet_req_init() had returned false and percpu_ref_tryget_live() was never executed. The unconditional percpu_ref_put() inside nvmet_req_uninit() then causes a refcount underflow, leading to a WARNING in percpu_ref_switch_to_atomic_rcu, a use-after-free diagnostic, and eventually a permanent workqueue deadlock.

Check cmd->flags & NVMET_TCP_F_INIT_FAILED before calling nvmet_req_uninit(), matching the existing pattern in nvmet_tcp_execute_request().

Product Status

Vendor Linux
Product Linux
Versions Default: unaffected
  • affected from 1da177e4c3f41524e886b7f1b8a0c1fc7321cac2 to 22ec7a9fe9153d2737ee9b2fa6d2e43a1491decf (excl.)
  • affected from 1da177e4c3f41524e886b7f1b8a0c1fc7321cac2 to ba35b1c674ca3841c0dfadd698f2c1b3ec542d4e (excl.)
  • affected from 1da177e4c3f41524e886b7f1b8a0c1fc7321cac2 to c7874dad84b20433c0fe3919f291a762d40de08b (excl.)
  • affected from 1da177e4c3f41524e886b7f1b8a0c1fc7321cac2 to e602c93b25bda4a9d0ff1791a4bdbfdcbb074af1 (excl.)
  • affected from 1da177e4c3f41524e886b7f1b8a0c1fc7321cac2 to d306da8833e75f669d93424fd84940236f3850bc (excl.)
  • affected from 1da177e4c3f41524e886b7f1b8a0c1fc7321cac2 to 2ed3c9d955e8cd6361f130623baa664a75fb345f (excl.)
  • affected from 1da177e4c3f41524e886b7f1b8a0c1fc7321cac2 to 4606467a75cfc16721937272ed29462a750b60c8 (excl.)
  • affected from 0 to 5.10.261 (excl.)
  • affected from 0 to 5.15.212 (excl.)
  • affected from 0 to 6.1.178 (excl.)
  • affected from 0 to 6.6.145 (excl.)
  • affected from 0 to 6.12.97 (excl.)
  • affected from 0 to 6.18.40 (excl.)
Vendor Linux
Product Linux
Versions Default: affected
  • unaffected from 5.10.261 to 5.10.* (incl.)
  • unaffected from 5.15.212 to 5.15.* (incl.)
  • unaffected from 6.1.178 to 6.1.* (incl.)
  • unaffected from 6.6.145 to 6.6.* (incl.)
  • unaffected from 6.12.97 to 6.12.* (incl.)
  • unaffected from 6.18.40 to 6.18.* (incl.)
  • unaffected from 7.1 to * (incl.)

References