Answer in brief
CVE-2026-64430 records a High severity (CVSS 7.5) vulnerability in NTB: epf: Avoid calling pci_irq_vector() from hardirq context. The current sources do not mark it as known exploited. The current feed maps Linux/Linux (generic), Linux/Linux (generic). Check affected ranges and fixed versions before updating.
Analysis pending evidence review
HOL Guard separates source facts from reviewed analysis. See the methodology.
CVSS is 7.5. The current sources do not mark it as known exploited. Treat this as a source-backed prioritization signal, not a statement about your environment.
Analysis status
Analysis pending evidence review
Factual feed record only; HOL analysis is not approved for indexing. Read the methodology.
The current feed maps Linux/Linux (generic), Linux/Linux (generic). Check affected ranges and fixed versions before updating.
| Product | Affected versions | Fixed versions |
|---|---|---|
| cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:* | Not reported | Not reported |
| Package | Affected range | Fixed version |
|---|---|---|
| Linux/Linuxgeneric | >=812ce2f8d14ea791edd88c36ebcc9017bf4c88cb <33bba331a4a5fee8b6026fe72eca13cceeec1b7b || >=812ce2f8d14ea791edd88c36ebcc9017bf4c88cb <aff271b12a1eb8c8b3da19223ae1a6abe1e8168b || >=812ce2f8d14ea791edd88c36ebcc9017bf4c88cb <1dba8444ac0100133d72374634f6d7451fff1ccc || >=812ce2f8d14ea791edd88c36ebcc9017bf4c88cb <174a97f21bf9c54fa37ec0f321692e862ea130a3 || >=812ce2f8d14ea791edd88c36ebcc9017bf4c88cb <f71e8d9875069fa73e335f63f02ec6e52e3aaa51 || >=812ce2f8d14ea791edd88c36ebcc9017bf4c88cb <6350df503897d57c5634f71b0767d48c3b837583 || >=812ce2f8d14ea791edd88c36ebcc9017bf4c88cb <4dcddc1c794d1c65eda68f1f8dd04a0fecc0870f | 33bba331a4a5fee8b6026fe72eca13cceeec1b7b, aff271b12a1eb8c8b3da19223ae1a6abe1e8168b, 1dba8444ac0100133d72374634f6d7451fff1ccc, 174a97f21bf9c54fa37ec0f321692e862ea130a3, f71e8d9875069fa73e335f63f02ec6e52e3aaa51, 6350df503897d57c5634f71b0767d48c3b837583, 4dcddc1c794d1c65eda68f1f8dd04a0fecc0870f |
| Linux/Linuxgeneric | 5.12 | Not reported |
Published upstream
Jul 25, 2026
Evidence: source:cvelist:source_dates:source-dates:recordSource modified
Sep 3, 2026
Evidence: source:cvelist:source_dates:source-dates:recordFirst seen by HOL
Aug 5, 2026
In the Linux kernel, the following vulnerability has been resolved: NTB: epf: Avoid calling pci_irq_vector() from hardirq context ntb_epf_vec_isr() calls pci_irq_vector() in hardirq context to derive the vector number. pci_irq_vector() calls msi_get_virq() that takes a mutex and can therefore trigger "scheduling while atomic" splats: BUG: scheduling while atomic: kworker/u33:0/55/0x00010001 ... Call trace: ... schedule+0x38/0x110 schedule_preempt_disabled+0x28/0x50 __mutex_lock.constprop.0+0x848/0x908 __mutex_lock_slowpath+0x18/0x30 mutex_lock+0x4c/0x60 msi_domain_get_virq+0xe8/0x138 pci_irq_vector+0x2c/0x60 ntb_epf_vec_isr+0x28/0x120 [ntb_hw_epf] __handle_irq_event_percpu+0x70/0x3a8 handle_irq_event+0x48/0x100 handle_edge_irq+0x100/0x1c8 ... Cache the Linux IRQ number for vector 0 when vectors are allocated and use it as a base in the ISR. Running the ISR in a threaded IRQ handler would also avoid the problem, but that would be unnecessary here.
Quoted source text, attributed separately from HOL analysis.