CVE-2026-64019
In the Linux kernel, the following vulnerability has been resolved: nvme-pci: fix dma mapping leak on data setup error We're leaking the initial DMA mapping during iteration if we fail to allocate the tracking descriptor for both PRP and SGL. Unmap the iterator directly; we can't use the existing unmap helper because it depends on the tracking descriptor being successfully allocated, so a new one for an in-use iterator is provided. The mappings were also leaking when the driver detects an invalid bio_vec when mapping PRPs, so fix that too.
Affected versions
Linux kernel versions
6.17
and later are affected. Fixed in
7.0.11,
7.1
and their respective stable series.
References
2 totalFrequently asked questions
-
What is CVE-2026-64019?
CVE-2026-64019 is a unscored severity Linux kernel vulnerability . It affects Linux kernel versions from 6.17 onward and has been patched in 7.0.11 and 7.1. CVE-2026-64019 has not been confirmed as actively exploited and is not listed in the CISA KEV catalog.
-
Is there a patch available for CVE-2026-64019?
Yes — CVE-2026-64019 has been patched. Fixed versions include 7.0.11 and 7.1. If you are running Linux kernel 6.17 or later up to the fix versions, apply the relevant patch for your kernel branch.
-
Is CVE-2026-64019 actively exploited?
No — CVE-2026-64019 has not been confirmed as actively exploited. It is not listed in the CISA Known Exploited Vulnerabilities (KEV) catalog.