CVE-2026-64232
A critical bug in the Linux kernel’s block layer can cause a kernel crash when handling certain storage requests. The flaw arises from incorrect counting of integrity segments in stacked queue setups, leading to a BUG_ON that aborts the request. The issue has been fixed in recent kernel releases.
An official fix is available, so this entry is kept for 30 days and then removed automatically.
Who is affected
Linux kernel, all versions prior to the patch that includes the fix. Typical users include system administrators, Linux users, servers, and embedded devices that rely on the kernel’s block I/O subsystem.
Real-world impact
An attacker could crash the system by sending specially crafted block requests, potentially causing a denial‑of‑service condition.
Why this severity
The CVSS score of 9.8 reflects a critical severity because the vulnerability is remotely exploitable without authentication or user interaction, and it can lead to a complete system crash or denial of service.
What to do about it
- 01Upgrade the Linux kernel to a version that includes the fix for the integrity segment accounting bug.
- 02Reboot the system to load the updated kernel.
NVD description indicates the vulnerability has been resolved in the Linux kernel.
Timeline
- Jul 24, 2026 · 8d agoPublishedDisclosed and added to the National Vulnerability Database.
- Jul 27, 2026 · 5d agoOfficial fix availableA vendor patch or mitigation now exists — see the remediation steps above.
- Jul 30, 2026 · 2d agoAdvisory updatedThe NVD record was last revised.