PT-2026-64697 · Linux+1 · Linux Kernel+1

CVE-2026-64476

·

Published

2026-07-25

·

Updated

2026-09-07

None

No severity ratings or metrics are available. When they are, we'll update the corresponding info on the page.
Name of the Vulnerable Software and Affected Versions Linux kernel (affected versions not specified)
Description An issue exists in the vfio-pci component where the disable idle d3 module parameter was handled as a global variable. When the vfio-pci module is loaded, unloaded, or reloaded with different values, it can change these globals relative to devices already bound to vfio-pci variant drivers. Since the introduction of Runtime PM (Power Management), power states are refcounted, requiring PM get and put operations to be balanced. The ability to change global variables during runtime creates a window where these PM operations can become unbalanced. The issue is further linked to the vfio pci dev set try reset() function and the use of pci set power state() for manipulating device power states.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Exploit

Found an issue in the description? Have something to add? Feel free to write us 👾

Related Identifiers

CVE-2026-64476
ECHO-99A9-D0AB-7A8E
OPENSUSE-SU-2026:11476-1
USN-8726-1
USN-8727-1
USN-8728-1

Affected Products

Linux Kernel
Ubuntu