Skip to main content

Over 150 LLM Providers · Over 5,300 Models The most extensible AI-powered pentesting platform. Open source. Star on GitHub

CVE-2026-64465

Published Jul 25, 2026 EPSS 0.18% (8th pctl)

Overview

CVE-2026-64465 is a known-severity vulnerability. It was published on July 25, 2026.

Technical Description

In the Linux kernel, the following vulnerability has been resolved:

usb: xhci: Fix sleep in atomic context in xhci_free_streams()

When a USB device with active stream endpoints is disconnected,

xhci_free_streams() is called from the hub_event workqueue to

free the stream resources. It calls xhci_free_stream_info()

while holding xhci->lock with irqs disabled.

xhci_free_stream_info() invokes xhci_free_stream_ctx(), which

calls dma_free_coherent() for large stream context arrays.

dma_free_coherent() can sleep (e.g. via vunmap), triggering

a BUG when called from atomic context.

Call trace:

dma_free_attrs+0x174/0x220

xhci_free_stream_info+0xd0/0x11c

xhci_free_streams+0x278/0x37c

usb_free_streams+0x98/0xc0

usb_unbind_interface+0x1b8/0x2f8

device_release_driver_internal+0x1d4/0x2cc

device_release_driver+0x18/0x28

bus_remove_device+0x160/0x1a4

device_del+0x1ec/0x350

usb_disable_device+0x98/0x214

usb_disconnect+0xf0/0x35c

hub_event+0xab4/0x19ec

process_one_work+0x278/0x63c

F

Remediation

Check the references section for vendor advisories, patches, and mitigation guidance. If immediate patching is not possible, review the CVSS vector to understand the attack surface and apply compensating controls such as network segmentation or access restrictions.

Frequently Asked Questions

What is CVE-2026-64465?

CVE-2026-64465 is a known-severity vulnerability. It was published on July 25, 2026.

How severe is CVE-2026-64465?

CVSS score information is not yet available for this vulnerability. Check back as the CVE record is updated by NVD analysts.

How do I fix or remediate CVE-2026-64465?

Check the references section for vendor advisories, patches, and mitigation guidance. If immediate patching is not possible, review the CVSS vector to understand the attack surface and apply compensating controls such as network segmentation or access restrictions.

How can CyberStrike help with CVE-2026-64465?

CyberStrike's AI-powered security agents can automatically detect CVE-2026-64465 across your infrastructure using autonomous pentesting, DAST scanning, and HackBrowser. The platform continuously monitors for known vulnerabilities and provides actionable remediation guidance prioritized by real-world exploitability.