Race condition in Linux kernel - CVE-2026-64430
Published: July 27, 2026
Vulnerability details
The vulnerability allows a local user to cause a denial of service.
The vulnerability exists due to improper resource access in the ntb_epf_vec_isr interrupt handler in drivers/ntb/hw/epf/ntb_hw_epf.c when handling interrupts and deriving the vector number through pci_irq_vector() in hardirq context. A local user can trigger the vulnerable interrupt handling path to cause a denial of service.
The issue can result in "scheduling while atomic" kernel splats because pci_irq_vector() reaches code that takes a mutex in hardirq context.
Affected software
Ubuntu
linux (Ubuntu package)
linux-azure (Ubuntu package)
linux-gcp-7.0 (Ubuntu package)
linux-oracle-7.0 (Ubuntu package)
linux-oem-7.0 (Ubuntu package)
linux-azure-7.0 (Ubuntu package)
How to mitigate CVE-2026-64430
linux (Ubuntu package) - addressed in versions 7.0.0-31.31, 7.0.0-31.31.1, 7.0.0-31.31~24.04.1, 7.0.0-1006.7, 7.0.0-1011.11~24.04.1, 7.0.0-1012.12, 7.0.0-1012.12~24.04.1
linux-azure (Ubuntu package) - addressed in versions 7.0.0-1011.11, 7.0.0-1014.14
linux-gcp-7.0 (Ubuntu package) - update to 7.0.0-1011.11~24.04.1
linux-oracle-7.0 (Ubuntu package) - update to 7.0.0-1011.11~24.04.1
linux-oem-7.0 (Ubuntu package) - update to 7.0.0-1013.13
linux-azure-7.0 (Ubuntu package) - update to 7.0.0-1014.14~24.04.1
External References
- https://git.kernel.org/stable/c/174a97f21bf9c54fa37ec0f321692e862ea130a3
- https://git.kernel.org/stable/c/1dba8444ac0100133d72374634f6d7451fff1ccc
- https://git.kernel.org/stable/c/33bba331a4a5fee8b6026fe72eca13cceeec1b7b
- https://git.kernel.org/stable/c/4dcddc1c794d1c65eda68f1f8dd04a0fecc0870f
- https://git.kernel.org/stable/c/6350df503897d57c5634f71b0767d48c3b837583
- https://git.kernel.org/stable/c/aff271b12a1eb8c8b3da19223ae1a6abe1e8168b
- https://git.kernel.org/stable/c/f71e8d9875069fa73e335f63f02ec6e52e3aaa51