Skip to main content

Over 150 LLM Providers · Over 5,300 Models The most extensible AI-powered pentesting platform. Open source. Star on GitHub

CVE-2026-64528

Published Jul 25, 2026 EPSS 0.17% (6th pctl)

Overview

CVE-2026-64528 is a known-severity vulnerability. It was published on July 25, 2026.

Technical Description

In the Linux kernel, the following vulnerability has been resolved:

tty: serial: samsung: Remove redundant port lock acquisition in rx helpers

Sashiko identified a deadlock when the console flow is engaged [1].

When console flow control is enabled (UPF_CONS_FLOW),

s3c24xx_serial_stop_tx() calls s3c24xx_serial_rx_enable() and

s3c24xx_serial_start_tx() calls s3c24xx_serial_rx_disable().

The serial core framework invokes the .stop_tx() and .start_tx()

callbacks with the port->lock spinlock already held. Furthermore, all

internal driver paths that invoke stop_tx (such as the DMA TX

completion handler s3c24xx_serial_tx_dma_complete() or the PIO TX IRQ

handler s3c24xx_serial_tx_irq()) also acquire port->lock prior to

calling it. (Note that s3c24xx_serial_start_tx() is only invoked by the

serial core).

However, s3c24xx_serial_rx_enable() and s3c24xx_serial_rx_disable()

unconditionally attempt to acquire port->lock again using

uart_port_lock_irqsave(). Since spinlocks are not recursive, t

Remediation

Check the references section for vendor advisories, patches, and mitigation guidance. If immediate patching is not possible, review the CVSS vector to understand the attack surface and apply compensating controls such as network segmentation or access restrictions.

Frequently Asked Questions

What is CVE-2026-64528?

CVE-2026-64528 is a known-severity vulnerability. It was published on July 25, 2026.

How severe is CVE-2026-64528?

CVSS score information is not yet available for this vulnerability. Check back as the CVE record is updated by NVD analysts.

How do I fix or remediate CVE-2026-64528?

Check the references section for vendor advisories, patches, and mitigation guidance. If immediate patching is not possible, review the CVSS vector to understand the attack surface and apply compensating controls such as network segmentation or access restrictions.

How can CyberStrike help with CVE-2026-64528?

CyberStrike's AI-powered security agents can automatically detect CVE-2026-64528 across your infrastructure using autonomous pentesting, DAST scanning, and HackBrowser. The platform continuously monitors for known vulnerabilities and provides actionable remediation guidance prioritized by real-world exploitability.