Skip to main content

Over 150 LLM Providers · Over 5,300 Models The most extensible AI-powered pentesting platform. Open source. Star on GitHub

CVE-2026-64021

Published Jul 19, 2026 EPSS 0.17% (6th pctl)

Overview

CVE-2026-64021 is a known-severity vulnerability. It was published on July 19, 2026.

Technical Description

In the Linux kernel, the following vulnerability has been resolved:

drm/xe/oa: Fix exec_queue leak on width check in stream open

In xe_oa_stream_open_ioctl(), when param.exec_q->width > 1 the

function returns -EOPNOTSUPP directly, skipping the existing

err_exec_q cleanup path. The exec_queue reference obtained by

xe_exec_queue_lookup() is leaked.

The exec queue holds a reference on the xe_file, which is only

dropped during queue teardown. The leaked lookup ref is not on

the file's exec_queue xarray, so file close cannot release it.

This keeps both the exec queue and the file private state pinned

indefinitely.

Jump to err_exec_q instead of returning directly so the reference

is released.

(cherry picked from commit 339fa0be9e4a5d69fa47e91f4a36574224fb478f)

Remediation

Check the references section for vendor advisories, patches, and mitigation guidance. If immediate patching is not possible, review the CVSS vector to understand the attack surface and apply compensating controls such as network segmentation or access restrictions.

Frequently Asked Questions

What is CVE-2026-64021?

CVE-2026-64021 is a known-severity vulnerability. It was published on July 19, 2026.

How severe is CVE-2026-64021?

CVSS score information is not yet available for this vulnerability. Check back as the CVE record is updated by NVD analysts.

How do I fix or remediate CVE-2026-64021?

Check the references section for vendor advisories, patches, and mitigation guidance. If immediate patching is not possible, review the CVSS vector to understand the attack surface and apply compensating controls such as network segmentation or access restrictions.

How can CyberStrike help with CVE-2026-64021?

CyberStrike's AI-powered security agents can automatically detect CVE-2026-64021 across your infrastructure using autonomous pentesting, DAST scanning, and HackBrowser. The platform continuously monitors for known vulnerabilities and provides actionable remediation guidance prioritized by real-world exploitability.