What is CVE-2026-64534?
A vulnerability in the Linux kernel's nvmet-tcp subsystem has been resolved. The `nvmet_req_uninit()` function was called without checking the `INIT_FAILED` flag during data digest mismatch, potentially leading to a security weakness. Affected systems should apply the kernel update.
Azərbaycanca: Linux kernel-in nvmet-tcp alt sistemində kritik boşluq aşkar edilib. Data digest xətası zamanı `INIT_FAILED` bayrağı yoxlanılmadığı üçün `nvmet_req_uninit()` funksiyası təhlükəsizlik zəifliyinə səbəb ola bilər. Təsirə məruz qalan sistemlərdə kernel yeniləməsi tətbiq edilməlidir.
FAQ2
Which subsystem of the Linux kernel is affected by CVE-2026-64534?
This vulnerability affects the nvmet-tcp subsystem of the Linux kernel.
What is the root cause of the vulnerability in CVE-2026-64534?
The security weakness is caused by the `nvmet_req_uninit()` function being called without checking the `INIT_FAILED` flag during a data digest mismatch.
See also6
This explainer is AI-written from source data — skopnix's own reporting on this CVE; CVSS scores, vendors and versions are never invented. See NVD for the official record.