PatchSiren cyber security CVE debrief
CVE-2026-64327 Linux CVE debrief
A Linux kernel vulnerability has been resolved, which could lead to incorrect DMA directions due to inaccurate endpoint direction checks. This issue affects Linux kernel versions 6.9, 6.13, 6.19, 7.2 rc1, and 7.2 rc2. The vulnerability is related to the usb gadget f_fs component, where the epfile->in was not initialized early, leading to incorrect endpoint direction checks. Defenders should verify and apply patches for affected Linux kernel versions, assess exposure in Linux kernel deployments, and inventory Linux kernel versions for potential exposure.
- Vendor
- Linux
- Product
- Unknown
- CVSS
- MEDIUM 5.5
- CISA KEV
- Not listed in stored evidence
- Original CVE published
- 2026-07-25
- Original CVE updated
- 2026-09-04
- Advisory published
- 2026-07-25
- Advisory updated
- 2026-09-04
Who should care
Linux kernel developers, administrators, and users who need to verify and apply patches for Linux kernel versions 6.9, 6.13, 6.19, 7.2 rc1, and 7.2 rc2. These individuals should assess exposure in Linux kernel deployments, inventory Linux kernel versions for potential exposure, and apply patches as needed.
Why it matters
CVE-2026-64327 is a Linux kernel vulnerability that could lead to incorrect DMA directions due to inaccurate endpoint direction checks. Defenders should verify and apply patches for affected Linux kernel versions, assess exposure in Linux kernel deployments, and inventory Linux kernel versions for potential exposure.
- Verify endpoint direction checks for Linux kernel versions 6.9, 6.13, 6.19, 7.2 rc1, and 7.2 rc2
- Assess exposure in Linux kernel deployments
- Apply patches for Linux kernel versions 6.9, 6.13, 6.19, 7.2 rc1, and 7.2 rc2
Technical summary
The Linux kernel vulnerability (CVE-2026-64327) is related to the usb gadget f_fs component, where the epfile->in was not initialized early, leading to incorrect endpoint direction checks. This issue affects Linux kernel versions 6.9, 6.13, 6.19, 7.2 rc1, and 7.2 rc2. Defenders should verify and apply patches for affected Linux kernel versions, assess exposure in Linux kernel deployments, and inventory Linux kernel versions for potential exposure. The vulnerability has been resolved by moving the initialization to ffs_epfiles_create(), ensuring epfile->in is accurate before userspace opens the endpoint files.
Defensive priority
Verify and apply patches for Linux kernel versions 6.9, 6.13, 6.19, 7.2 rc1, and 7.2 rc2; assess exposure in Linux kernel deployments.
Recommended defensive actions
- Verify Linux kernel version and apply patches for versions 6.9, 6.13, 6.19, 7.2 rc1, and 7.2 rc2
- Assess exposure in Linux kernel deployments
- Inventory Linux kernel versions for potential exposure
- Review compensating controls for exposed systems while remediation is scheduled and verified
- Check relevant monitoring, detection, and logs for exposed assets that need extra review
- Track exceptions, retest remediated assets, and close the item only after evidence is documented
- Confirm whether affected product deployments exist in managed environments and assign an owner for follow-up
Evidence notes
The CVE record and NVD vulnerability detail provide information on the vulnerability, its CVSS score, and affected Linux kernel versions. The vulnerability has been resolved in Linux kernel versions 6.9, 6.13, 6.19, 7.2 rc1, and 7.2 rc2. Defenders should verify endpoint direction checks for these versions, assess exposure in Linux kernel deployments, and apply patches as needed. The source detail is limited, so defenders should exercise caution when verifying and applying patches.
Sources and references
Verified primary and authoritative sources
-
CVE-2026-64327 CVE Program record
Publisher, destination, and source semantics verified
URL: https://www.cve.org/CVERecord?id=CVE-2026-64327
CVE Program - Official CVE Program record with source-provided CVE metadata.
-
CVE-2026-64327 NVD vulnerability detail
Publisher, destination, and source semantics verified
URL: https://nvd.nist.gov/vuln/detail/CVE-2026-64327
NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.
Supplemental references
-
Source reference
Unverified legacy reference
URL: https://git.kernel.org/stable/c/82cf1142e5ccf2b6d6d22ef713aaf3e5f2b5716b
416baaa9-dc9f-4396-8d5f-8c081fb06d67 - Patch
-
Source reference
Unverified legacy reference
URL: https://git.kernel.org/stable/c/82cfd4739011bdc7e87b5d585703427e89ddfaa5
416baaa9-dc9f-4396-8d5f-8c081fb06d67 - Patch
-
Source reference
Unverified legacy reference
URL: https://git.kernel.org/stable/c/9e04055ab5fc0470a0031ee6934739f9aa8f34a5
416baaa9-dc9f-4396-8d5f-8c081fb06d67 - Patch
-
Source reference
Unverified legacy reference
URL: https://git.kernel.org/stable/c/f99f32ea9aa976afcbec20647ed33b50a52002c1
416baaa9-dc9f-4396-8d5f-8c081fb06d67 - Patch
Methodology and review provenance
AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.