{"id":"CVE-2026-64465","summary":"usb: xhci: Fix sleep in atomic context in xhci_free_streams()","details":"In the Linux kernel, the following vulnerability has been resolved:\n\nusb: xhci: Fix sleep in atomic context in xhci_free_streams()\n\nWhen a USB device with active stream endpoints is disconnected,\nxhci_free_streams() is called from the hub_event workqueue to\nfree the stream resources.  It calls xhci_free_stream_info()\nwhile holding xhci-\u003elock with irqs disabled.\n\nxhci_free_stream_info() invokes xhci_free_stream_ctx(), which\ncalls dma_free_coherent() for large stream context arrays.\n\ndma_free_coherent() can sleep (e.g. via vunmap), triggering\na BUG when called from atomic context.\n\nCall trace:\n dma_free_attrs+0x174/0x220\n xhci_free_stream_info+0xd0/0x11c\n xhci_free_streams+0x278/0x37c\n usb_free_streams+0x98/0xc0\n usb_unbind_interface+0x1b8/0x2f8\n device_release_driver_internal+0x1d4/0x2cc\n device_release_driver+0x18/0x28\n bus_remove_device+0x160/0x1a4\n device_del+0x1ec/0x350\n usb_disable_device+0x98/0x214\n usb_disconnect+0xf0/0x35c\n hub_event+0xab4/0x19ec\n process_one_work+0x278/0x63c\n\nFix this by saving the stream_info pointers and clearing the\nep references under the lock, then calling xhci_free_stream_info()\noutside the lock where sleeping is allowed.","modified":"2026-07-27T04:03:22.175967335Z","published":"2026-07-25T08:51:31.160Z","database_specific":{"cna_assigner":"Linux","osv_generated_from":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/64xxx/CVE-2026-64465.json"},"references":[{"type":"WEB","url":"https://git.kernel.org/stable/c/10666ac9c552990204e791af653abf8e9d9ff619"},{"type":"WEB","url":"https://git.kernel.org/stable/c/1e45aa722c4ce5663e987102aac18c8ad6a83fdd"},{"type":"WEB","url":"https://git.kernel.org/stable/c/42c37c4b75d38b51d84f31a8e29427f5e06a7c2a"},{"type":"WEB","url":"https://git.kernel.org/stable/c/93cd037da94fcb93183bfb2457e3a56d3eb4c8f4"},{"type":"WEB","url":"https://git.kernel.org/stable/c/d107eb316144c5fb958486e7fe604cd7f1b35cda"},{"type":"WEB","url":"https://git.kernel.org/stable/c/e623e4a203f56d5c57519a9a3cb29600551534ad"},{"type":"WEB","url":"https://git.kernel.org/stable/c/f7b022ae07685e7526fc39f387ce65b5d309dd3b"},{"type":"WEB","url":"https://git.kernel.org/stable/c/f90586129cf9e1fbdb718ef602eea3f15dc1c31c"},{"type":"ADVISORY","url":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/64xxx/CVE-2026-64465.json"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-64465"},{"type":"PACKAGE","url":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git"}],"affected":[{"ranges":[{"type":"GIT","repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","events":[{"introduced":"8df75f42f8e67e2851cdcf6da91640fb881defd1"},{"fixed":"e623e4a203f56d5c57519a9a3cb29600551534ad"},{"fixed":"d107eb316144c5fb958486e7fe604cd7f1b35cda"},{"fixed":"1e45aa722c4ce5663e987102aac18c8ad6a83fdd"},{"fixed":"10666ac9c552990204e791af653abf8e9d9ff619"},{"fixed":"f7b022ae07685e7526fc39f387ce65b5d309dd3b"},{"fixed":"f90586129cf9e1fbdb718ef602eea3f15dc1c31c"},{"fixed":"93cd037da94fcb93183bfb2457e3a56d3eb4c8f4"},{"fixed":"42c37c4b75d38b51d84f31a8e29427f5e06a7c2a"}]}],"database_specific":{"source":"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-64465.json"}},{"package":{"name":"Kernel","ecosystem":"Linux"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"2.6.35"},{"fixed":"5.10.261"}]},{"type":"ECOSYSTEM","events":[{"introduced":"5.11.0"},{"fixed":"5.15.212"}]},{"type":"ECOSYSTEM","events":[{"introduced":"5.16.0"},{"fixed":"6.1.178"}]},{"type":"ECOSYSTEM","events":[{"introduced":"6.2.0"},{"fixed":"6.6.145"}]},{"type":"ECOSYSTEM","events":[{"introduced":"6.7.0"},{"fixed":"6.12.96"}]},{"type":"ECOSYSTEM","events":[{"introduced":"6.13.0"},{"fixed":"6.18.39"}]},{"type":"ECOSYSTEM","events":[{"introduced":"6.19.0"},{"fixed":"7.1.4"}]}],"database_specific":{"source":"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-64465.json"}}],"schema_version":"1.7.5"}