CVE-2026-64465
Received Received - Intake

Sleep in Atomic Context in Linux Kernel USB XHCI Driver

Vulnerability report for CVE-2026-64465, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-07-25

Last updated on: 2026-07-25

Assigner: kernel.org

Description

In the Linux kernel, the following vulnerability has been resolved: usb: xhci: Fix sleep in atomic context in xhci_free_streams() When a USB device with active stream endpoints is disconnected, xhci_free_streams() is called from the hub_event workqueue to free the stream resources. It calls xhci_free_stream_info() while holding xhci->lock with irqs disabled. xhci_free_stream_info() invokes xhci_free_stream_ctx(), which calls dma_free_coherent() for large stream context arrays. dma_free_coherent() can sleep (e.g. via vunmap), triggering a BUG when called from atomic context. Call trace: dma_free_attrs+0x174/0x220 xhci_free_stream_info+0xd0/0x11c xhci_free_streams+0x278/0x37c usb_free_streams+0x98/0xc0 usb_unbind_interface+0x1b8/0x2f8 device_release_driver_internal+0x1d4/0x2cc device_release_driver+0x18/0x28 bus_remove_device+0x160/0x1a4 device_del+0x1ec/0x350 usb_disable_device+0x98/0x214 usb_disconnect+0xf0/0x35c hub_event+0xab4/0x19ec process_one_work+0x278/0x63c Fix this by saving the stream_info pointers and clearing the ep references under the lock, then calling xhci_free_stream_info() outside the lock where sleeping is allowed.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-07-25
Last Modified
2026-07-25
Generated
2026-08-14
AI Q&A
2026-07-25
EPSS Evaluated
2026-08-13
NVD
EUVD

Affected Vendors & Products

Showing 1 associated CPE
Vendor Product Version / Range
linux linux_kernel *

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-UNKNOWN

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

This vulnerability is in the Linux kernel's USB xHCI driver. When a USB device with active stream endpoints is disconnected, the kernel tries to free stream resources while holding a lock with interrupts disabled. The function dma_free_coherent() is then called, which can sleep, causing a BUG in atomic context.

Detection Guidance

This vulnerability is specific to the Linux kernel's USB XHCI driver and may not have direct network detection methods. Monitor kernel logs for BUG messages or crashes related to USB device disconnections, particularly involving xhci_free_streams or dma_free_coherent. Check for kernel oops or warnings in /var/log/kern.log or dmesg output.

Impact Analysis

This could cause system crashes or instability when disconnecting certain USB devices. The system may freeze or trigger a kernel panic due to the BUG in atomic context, potentially leading to data loss or requiring a reboot.

Compliance Impact

This vulnerability does not directly affect compliance with standards like GDPR or HIPAA as it is a kernel-level issue causing system instability rather than a data breach or privacy violation.

Mitigation Strategies

Update the Linux kernel to a patched version that includes the fix for this issue. Avoid unplugging USB devices with active streams while the system is under heavy I/O load. If kernel updates are unavailable, consider disabling USB stream functionality if not critical to operations.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-64465. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart