Skip to main content

Over 150 LLM Providers · Over 5,300 Models The most extensible AI-powered pentesting platform. Open source. Star on GitHub

CVE-2026-64476

Published Jul 25, 2026 EPSS 0.18% (8th pctl)

Overview

CVE-2026-64476 is a known-severity vulnerability. It was published on July 25, 2026.

Technical Description

In the Linux kernel, the following vulnerability has been resolved:

vfio/pci: Latch disable_idle_d3 per device

When disable_idle_d3 was introduced in vfio-pci, it directly manipulated

the device power state with pci_set_power_state(). There were no

refcounts to maintain or balanced operations, we could unconditionally

bring the device to D0 and conditionally move it to D3hot. Therefore

the module parameter was made writable.

Later, in commit c61302aa48f7 ("vfio/pci: Move module parameters to

vfio_pci.c"), as part of the vfio-pci-core split, the writable aspect

of the module parameter was nullified. The parameter value could still

be changed through sysfs, but the vfio-pci driver latched the values

into vfio-pci-core globals at module init. Loading the vfio-pci module,

or unloading and reloading, with non-default or different values could

change the globals relative to existing devices bound to vfio-pci

variant drivers.

Runtime PM was introduced in commit 7ab5e10eda02 ("vfio/pci

Remediation

Check the references section for vendor advisories, patches, and mitigation guidance. If immediate patching is not possible, review the CVSS vector to understand the attack surface and apply compensating controls such as network segmentation or access restrictions.

Frequently Asked Questions

What is CVE-2026-64476?

CVE-2026-64476 is a known-severity vulnerability. It was published on July 25, 2026.

How severe is CVE-2026-64476?

CVSS score information is not yet available for this vulnerability. Check back as the CVE record is updated by NVD analysts.

How do I fix or remediate CVE-2026-64476?

Check the references section for vendor advisories, patches, and mitigation guidance. If immediate patching is not possible, review the CVSS vector to understand the attack surface and apply compensating controls such as network segmentation or access restrictions.

How can CyberStrike help with CVE-2026-64476?

CyberStrike's AI-powered security agents can automatically detect CVE-2026-64476 across your infrastructure using autonomous pentesting, DAST scanning, and HackBrowser. The platform continuously monitors for known vulnerabilities and provides actionable remediation guidance prioritized by real-world exploitability.