🟠 High | Source: Microsoft Security Response Center
CVE-2026-64017 is a Linux kernel vulnerability in the blk-mq (block multi-queue) subsystem, affecting how cached I/O requests are handled. Microsoft has published an advisory via the MSRC, indicating it affects Azure infrastructure or Azure-hosted Linux workloads. Depending on exploitability, this type of kernel-level flaw can potentially be leveraged for privilege escalation or denial of service within affected environments.
Security Architect’s Take: Review whether your Azure Linux VMs or AKS node pools are running kernel versions affected by this blk-mq flaw, and apply any available OS or platform patches promptly. Monitor Microsoft’s MSRC advisory page for updated severity scores and patch guidance as details emerge.
Original advisory: CVE-2026-64017 blk-mq: pop cached request if it is usable