Junglewise Threat Intelligence

CVE-2026-64464: Linux Kernel memory leak in xHCI sideband driver

CVE-2026-64464 · Severity: info · Published 2026-07-25

Technologies: Linux Kernel. Vendors: Linux.

Executive brief

A memory leak was identified in the Linux kernel's USB xHCI sideband driver. This component manages high-speed USB data transfers between the computer and peripheral devices. If exploited or triggered repeatedly, this flaw could cause the system to slowly run out of available memory, potentially leading to system instability or a crash.

Technical details

A memory leak exists in the xhci_ring_to_sgtable() function within drivers/usb/host/xhci-sideband.c. The function allocates a temporary pages array to construct an sg_table using sg_alloc_table_from_pages(). While error paths correctly handle memory cleanup, the success path fails to call kvfree() on the temporary array after the sg_table is built. This results in a leak of the temporary array every time a sideband client requests an endpoint or event ring buffer. The vulnerability is resolved by explicitly freeing the temporary array once the sg_table construction is complete.

Affected products

  • Linux Linux Kernel 6.16 to 6.18.39, 7.1.4, 7.2-rc3

Timeline

  • 2026-07-25: disclosed
  • 2026-07-25: advisory

References

Related threats