PatchSiren

PatchSiren cyber security CVE debrief

CVE-2026-64327 Linux CVE debrief

A Linux kernel vulnerability has been resolved, which could lead to incorrect DMA directions due to inaccurate endpoint direction checks. This issue affects Linux kernel versions 6.9, 6.13, 6.19, 7.2 rc1, and 7.2 rc2. The vulnerability is related to the usb gadget f_fs component, where the epfile->in was not initialized early, leading to incorrect endpoint direction checks. Defenders should verify and apply patches for affected Linux kernel versions, assess exposure in Linux kernel deployments, and inventory Linux kernel versions for potential exposure.

Vendor
Linux
Product
Unknown
CVSS
MEDIUM 5.5
CISA KEV
Not listed in stored evidence
Original CVE published
2026-07-25
Original CVE updated
2026-09-04
Advisory published
2026-07-25
Advisory updated
2026-09-04

Who should care

Linux kernel developers, administrators, and users who need to verify and apply patches for Linux kernel versions 6.9, 6.13, 6.19, 7.2 rc1, and 7.2 rc2. These individuals should assess exposure in Linux kernel deployments, inventory Linux kernel versions for potential exposure, and apply patches as needed.

Why it matters

CVE-2026-64327 is a Linux kernel vulnerability that could lead to incorrect DMA directions due to inaccurate endpoint direction checks. Defenders should verify and apply patches for affected Linux kernel versions, assess exposure in Linux kernel deployments, and inventory Linux kernel versions for potential exposure.

  • Verify endpoint direction checks for Linux kernel versions 6.9, 6.13, 6.19, 7.2 rc1, and 7.2 rc2
  • Assess exposure in Linux kernel deployments
  • Apply patches for Linux kernel versions 6.9, 6.13, 6.19, 7.2 rc1, and 7.2 rc2

Technical summary

The Linux kernel vulnerability (CVE-2026-64327) is related to the usb gadget f_fs component, where the epfile->in was not initialized early, leading to incorrect endpoint direction checks. This issue affects Linux kernel versions 6.9, 6.13, 6.19, 7.2 rc1, and 7.2 rc2. Defenders should verify and apply patches for affected Linux kernel versions, assess exposure in Linux kernel deployments, and inventory Linux kernel versions for potential exposure. The vulnerability has been resolved by moving the initialization to ffs_epfiles_create(), ensuring epfile->in is accurate before userspace opens the endpoint files.

Defensive priority

Verify and apply patches for Linux kernel versions 6.9, 6.13, 6.19, 7.2 rc1, and 7.2 rc2; assess exposure in Linux kernel deployments.

Recommended defensive actions

  • Verify Linux kernel version and apply patches for versions 6.9, 6.13, 6.19, 7.2 rc1, and 7.2 rc2
  • Assess exposure in Linux kernel deployments
  • Inventory Linux kernel versions for potential exposure
  • Review compensating controls for exposed systems while remediation is scheduled and verified
  • Check relevant monitoring, detection, and logs for exposed assets that need extra review
  • Track exceptions, retest remediated assets, and close the item only after evidence is documented
  • Confirm whether affected product deployments exist in managed environments and assign an owner for follow-up

Evidence notes

The CVE record and NVD vulnerability detail provide information on the vulnerability, its CVSS score, and affected Linux kernel versions. The vulnerability has been resolved in Linux kernel versions 6.9, 6.13, 6.19, 7.2 rc1, and 7.2 rc2. Defenders should verify endpoint direction checks for these versions, assess exposure in Linux kernel deployments, and apply patches as needed. The source detail is limited, so defenders should exercise caution when verifying and applying patches.

Sources and references

Verified primary and authoritative sources

  • CVE-2026-64327 CVE Program record

    Publisher, destination, and source semantics verified

    URL: https://www.cve.org/CVERecord?id=CVE-2026-64327

    CVE Program - Official CVE Program record with source-provided CVE metadata.

  • CVE-2026-64327 NVD vulnerability detail

    Publisher, destination, and source semantics verified

    URL: https://nvd.nist.gov/vuln/detail/CVE-2026-64327

    NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.

Supplemental references

  • Source reference

    Unverified legacy reference

    URL: https://git.kernel.org/stable/c/82cf1142e5ccf2b6d6d22ef713aaf3e5f2b5716b

    416baaa9-dc9f-4396-8d5f-8c081fb06d67 - Patch

  • Source reference

    Unverified legacy reference

    URL: https://git.kernel.org/stable/c/82cfd4739011bdc7e87b5d585703427e89ddfaa5

    416baaa9-dc9f-4396-8d5f-8c081fb06d67 - Patch

  • Source reference

    Unverified legacy reference

    URL: https://git.kernel.org/stable/c/9e04055ab5fc0470a0031ee6934739f9aa8f34a5

    416baaa9-dc9f-4396-8d5f-8c081fb06d67 - Patch

  • Source reference

    Unverified legacy reference

    URL: https://git.kernel.org/stable/c/f99f32ea9aa976afcbec20647ed33b50a52002c1

    416baaa9-dc9f-4396-8d5f-8c081fb06d67 - Patch

Methodology and review provenance

AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.