Race condition in Linux kernel - CVE-2026-64430
Published: July 27, 2026
Vulnerability details
The vulnerability allows a local user to cause a denial of service.
The vulnerability exists due to improper resource access in the ntb_epf_vec_isr interrupt handler in drivers/ntb/hw/epf/ntb_hw_epf.c when handling interrupts and deriving the vector number through pci_irq_vector() in hardirq context. A local user can trigger the vulnerable interrupt handling path to cause a denial of service.
The issue can result in "scheduling while atomic" kernel splats because pci_irq_vector() reaches code that takes a mutex in hardirq context.
Affected software
How to mitigate CVE-2026-64430
External References
- https://git.kernel.org/stable/c/174a97f21bf9c54fa37ec0f321692e862ea130a3
- https://git.kernel.org/stable/c/1dba8444ac0100133d72374634f6d7451fff1ccc
- https://git.kernel.org/stable/c/33bba331a4a5fee8b6026fe72eca13cceeec1b7b
- https://git.kernel.org/stable/c/4dcddc1c794d1c65eda68f1f8dd04a0fecc0870f
- https://git.kernel.org/stable/c/6350df503897d57c5634f71b0767d48c3b837583
- https://git.kernel.org/stable/c/aff271b12a1eb8c8b3da19223ae1a6abe1e8168b
- https://git.kernel.org/stable/c/f71e8d9875069fa73e335f63f02ec6e52e3aaa51