CVE-2026-64017
In the Linux kernel, the following vulnerability has been resolved:
blk-mq: pop cached request if it is usable
When submitting a bio to blk-mq, if the task should sleep after peeking a cached request, but before it pops it, the plug flushes and calls blk_mq_free_plug_rqs, freeing the cached_rqs. This creates a use-after-free bug. Fix this by popping the cached request before any possible blocking calls if it is suitable for use.
Popping this request first holds a queue reference, so avoid any serialization races with queue freezes and can safely proceed with dispatching that request to the driver.
Leer descripción completaMostrar menos
This potentially increases a timing window from when a driver wants to freeze its queue to when requests stop being dispatched. That scenario is off the fast path though, and drivers need to appropriately handle requests during a freeze request anyway.
The downside is the popped element needs to be individually freed when we performed a bio plug merge. The cached request would have had to be freed later anyway, but this patch does it inline with building the plug list instead of after flushing it.
CVSS
- Versión: 3.1
- Vector: CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
- Puntuación base: 7.8
Probabilidad de explotación (EPSS)
- Probabilidad de explotación en los próximos 30 días: 0.13%
- Percentil entre todas las CVEs puntuadas: 2
- Fecha de la puntuación: 6/10/2026
EPSS (Exploit Prediction Scoring System, de FIRST) estima la probabilidad de que una vulnerabilidad sea explotada en 30 días. Complementa a CVSS (impacto) y a CISA KEV (explotación confirmada).
🎯 Técnicas ATT&CK
Cómo se explota esta vulnerabilidad y qué consigue el atacante, en el lenguaje de MITRE ATT&CK.
- Explotación
T1068Exploitation for Privilege Escalationprivilege escalation85 % - Impacto principal
T1499.004Application or System Exploitationimpact70 % - Impacto secundario
T1565.001Stored Data Manipulationimpact60 %
Use-after-free en kernel Linux con acceso local (AV:L/PR:L) permite escalada de privilegios o DoS. Explotable por tarea local sin interacción del usuario.
Inferido por nuestro agente de análisis a partir de la descripción oficial, el vector CVSS y la CWE, y comprobado por un supervisor. Puede contener errores.
🛡️ Mitigaciones ATT&CK que cubren estas técnicas
Tecnologías afectadas (1)
⚠ Inferidas por IA a partir de la descripción — NVD aún no ha analizado esta CVE; no son CPE verificados.
Referencias
JSON original (NVD)
Mostrar
{
"id": "CVE-2026-64017",
"cveTags": [],
"metrics": {
"cvssMetricV31": [
{
"type": "Secondary",
"source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"cvssData": {
"scope": "UNCHANGED",
"version": "3.1",
"baseScore": 7.8,
"attackVector": "LOCAL",
"baseSeverity": "HIGH",
"vectorString": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H",
"integrityImpact": "HIGH",
"userInteraction": "NONE",
"attackComplexity": "LOW",
"availabilityImpact": "HIGH",
"privilegesRequired": "LOW",
"confidentialityImpact": "HIGH"
},
"impactScore": 5.9,
"exploitabilityScore": 1.8
}
]
},
"affected": [
{
"source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"affectedData": [
{
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"product": "Linux",
"versions": [
{
"status": "affected",
"version": "b0077e269f6c152e807fdac90b58caf012cdbaab",
"lessThan": "23d8ea1e303b5f32d883757a4a707e791dbc9808",
"versionType": "git"
},
{
"status": "affected",
"version": "b0077e269f6c152e807fdac90b58caf012cdbaab",
"lessThan": "97e2d08de282ef76f84ab4ccd00f1acb3f5f999e",
"versionType": "git"
},
{
"status": "affected",
"version": "b0077e269f6c152e807fdac90b58caf012cdbaab",
"lessThan": "388468f7e7d1eab092cf2a39fdfb502e52019ec6",
"versionType": "git"
},
{
"status": "affected",
"version": "b0077e269f6c152e807fdac90b58caf012cdbaab",
"lessThan": "dc278e9bf2b9513a763353e6b9cc21e0f532954e",
"versionType": "git"
},
{
"status": "affected",
"version": "b5c8e0ff76d10f6bf70a7237678f27c20cf59bc9",
"versionType": "git"
},
{
"status": "affected",
"version": "e9c309ded295b7f8849097d71ae231456ca79f78",
"versionType": "git"
},
{
"status": "affected",
"version": "b80056bd75a16e4550873ecefe12bc8fd190b1cf",
"versionType": "git"
},
{
"status": "affected",
"version": "33cf52b6e53a6aa55883aa7fb9ceffceff8488a6",
"versionType": "git"
},
{
"status": "affected",
"version": "8b6075046470c8756242dfe3fd058813636f69a3",
"versionType": "git"
},
{
"status": "affected",
"version": "6.1.72",
"lessThan": "6.2",
"versionType": "semver"
},
{
"status": "affected",
"version": "6.5.13",
"lessThan": "6.6",
"versionType": "semver"
},
{
"status": "affected",
"version": "6.6.3",
"lessThan": "6.7",
"versionType": "semver"
},
{
"status": "affected",
"version": "6.1.75",
"lessThan": "6.2",
"versionType": "semver"
},
{
"status": "affected",
"version": "6.6.14",
"lessThan": "6.7",
"versionType": "semver"
}
],
"programFiles": [
"block/blk-mq.c"
],
"defaultStatus": "unaffected"
},
{
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"product": "Linux",
"versions": [
{
"status": "affected",
"version": "6.7"
},
{
"status": "unaffected",
"version": "0",
"lessThan": "6.7",
"versionType": "semver"
},
{
"status": "unaffected",
"version": "6.12.104",
"versionType": "semver",
"lessThanOrEqual": "6.12.*"
},
{
"status": "unaffected",
"version": "6.18.45",
"versionType": "semver",
"lessThanOrEqual": "6.18.*"
},
{
"status": "unaffected",
"version": "7.0.11",
"versionType": "semver",
"lessThanOrEqual": "7.0.*"
},
{
"status": "unaffected",
"version": "7.1",
"versionType": "original_commit_for_fix",
"lessThanOrEqual": "*"
}
],
"programFiles": [
"block/blk-mq.c"
],
"defaultStatus": "affected"
}
]
}
],
"published": "2026-07-19T16:17:41.680",
"references": [
{
"url": "https://git.kernel.org/stable/c/23d8ea1e303b5f32d883757a4a707e791dbc9808",
"source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
},
{
"url": "https://git.kernel.org/stable/c/388468f7e7d1eab092cf2a39fdfb502e52019ec6",
"source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
},
{
"url": "https://git.kernel.org/stable/c/97e2d08de282ef76f84ab4ccd00f1acb3f5f999e",
"source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
},
{
"url": "https://git.kernel.org/stable/c/dc278e9bf2b9513a763353e6b9cc21e0f532954e",
"source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
}
],
"vulnStatus": "Awaiting Analysis",
"descriptions": [
{
"lang": "en",
"value": "In the Linux kernel, the following vulnerability has been resolved:\n\nblk-mq: pop cached request if it is usable\n\nWhen submitting a bio to blk-mq, if the task should sleep after peeking\na cached request, but before it pops it, the plug flushes and calls\nblk_mq_free_plug_rqs, freeing the cached_rqs. This creates a\nuse-after-free bug. Fix this by popping the cached request before any\npossible blocking calls if it is suitable for use.\n\nPopping this request first holds a queue reference, so avoid any\nserialization races with queue freezes and can safely proceed with\ndispatching that request to the driver. This potentially increases a\ntiming window from when a driver wants to freeze its queue to when\nrequests stop being dispatched. That scenario is off the fast path\nthough, and drivers need to appropriately handle requests during a\nfreeze request anyway.\n\nThe downside is the popped element needs to be individually freed when\nwe performed a bio plug merge. The cached request would have had to be\nfreed later anyway, but this patch does it inline with building the plug\nlist instead of after flushing it."
}
],
"lastModified": "2026-08-19T17:20:14.617",
"sourceIdentifier": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
}