A vulnerability described as very critical has been identified in Linux Kernel up to 6.1.177/6.6.144/6.12.96/6.18.39. Impacted is the function nvmet_tcp_try_recv_ddgst of the component nvmet-tcp. The manipulation results in use after free.

This vulnerability was named CVE-2026-64535. The attack may be performed from remote. There is no available exploit.

Upgrading the affected component is recommended.