Improper update of reference count in Linux kernel - CVE-2026-64345
Published: July 27, 2026
Vulnerability identifier: #VU139636
CSH Severity: Low
CVSS v4: 4.8 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N]
CVE-ID: CVE-2026-64345
CWE-ID: CWE-911
Exploitation vector: Local access
Exploit availability:
No public exploit available
Vulnerability details
The vulnerability allows a local user to cause a denial of service.
The vulnerability exists due to improper reference count handling in the printer_open function in the f_printer USB gadget driver when opening the character device while it is already open. A local user can repeatedly attempt a second open to cause a denial of service.
Affected software
Linux kernel
How to mitigate CVE-2026-64345
Install security update from vendor's repository.
Linux kernel - update to 7.0 rc3
External References
- https://git.kernel.org/stable/c/30adce93d5c4a5a1ec29d9249e3fdfcc391d406b
- https://git.kernel.org/stable/c/75c0ad13e136961328253742501b4efc3988a587
- https://git.kernel.org/stable/c/7f1f24c367938c5537e2308bf9a965f051d14774
- https://git.kernel.org/stable/c/8a5eba992c862b0c94411eecf9b7121e8636db38
- https://git.kernel.org/stable/c/94ec20d97aa51547965a539f660a1fe79c6929a3
- https://git.kernel.org/stable/c/bf20c94fa6aaff945f0ae3a23f3212cd299f28d9