Skip to main content

Over 150 LLM Providers · Over 5,300 Models The most extensible AI-powered pentesting platform. Open source. Star on GitHub

CVE-2026-64329

Published Jul 25, 2026 EPSS 0.18% (7th pctl)

Overview

CVE-2026-64329 is a known-severity vulnerability. It was published on July 25, 2026.

Technical Description

In the Linux kernel, the following vulnerability has been resolved:

usb: typec: ucsi: ccg: Fix use-after-free of ucsi on remove

The threaded IRQ handler ccg_irq_handler() calls ucsi_notify_common(),

which on a connector-change event calls ucsi_connector_change() and

schedules connector work. In ucsi_ccg_remove(), ucsi_destroy() frees

uc->ucsi (kfree) before free_irq() is called, so a handler invocation

already in flight may access the freed object after ucsi_destroy().

CPU 0 (remove) | CPU 1 (threaded IRQ)

ucsi_destroy(uc->ucsi) | ccg_irq_handler()

kfree(ucsi) // FREE | ucsi_notify_common(uc->ucsi) // USE

Move free_irq() before ucsi_destroy() in the remove path. It is kept

after ucsi_unregister(): ucsi_unregister() cancels connector work whose

handler issues GET_CONNECTOR_STATUS through ucsi_send_command_common(),

which waits for a completion that is signalled from the IRQ handler, so

the IRQ must stay active until that work has been cancelled.

Th

Remediation

Check the references section for vendor advisories, patches, and mitigation guidance. If immediate patching is not possible, review the CVSS vector to understand the attack surface and apply compensating controls such as network segmentation or access restrictions.

Frequently Asked Questions

What is CVE-2026-64329?

CVE-2026-64329 is a known-severity vulnerability. It was published on July 25, 2026.

How severe is CVE-2026-64329?

CVSS score information is not yet available for this vulnerability. Check back as the CVE record is updated by NVD analysts.

How do I fix or remediate CVE-2026-64329?

Check the references section for vendor advisories, patches, and mitigation guidance. If immediate patching is not possible, review the CVSS vector to understand the attack surface and apply compensating controls such as network segmentation or access restrictions.

How can CyberStrike help with CVE-2026-64329?

CyberStrike's AI-powered security agents can automatically detect CVE-2026-64329 across your infrastructure using autonomous pentesting, DAST scanning, and HackBrowser. The platform continuously monitors for known vulnerabilities and provides actionable remediation guidance prioritized by real-world exploitability.