CSIRTS // UNIFIED SECURITY ADVISORY FEEDSYS ● ONLINE · POWERED BY INTELFUSIONS.COM

CVE-2026-45855

highCVSS 5.5covered by 14 sourcesfirst seen 2026-07-20
It was discovered that some AMD processors did not properly clear data in the floating point divider unit during speculative execution. A local attacker could use this to expose sensitive information. (CVE-2025-54505) It was discovered that some AMD Zen 2 processors did not properly isolate shared resources in the operation cache. A local attacker could possibly use this issue to corrupt instructions executed at a higher privilege level, resulting in privilege escalation. (CVE-2025-54518) It was discovered that some AMD Zen 5 processors supporting RDSEED instruction did not properly handle entropy, potentially resulting in the consumption of insufficiently random values. A local attacker could possibly use this issue to influence the values returned by the RDSEED instruction causing loss of confidentiality and integrity. (CVE-2025-62626) Several security issues were discovered in the Linux kernel. An attacker could possibly use these to compromise the system. This update corrects flaws in the following subsystems: - ARM64 architecture; - MIPS architecture; - PowerPC architecture; - RISC-V architecture; - S390 architecture; - x86 architecture; - Block layer subsystem; - Cryptographic API; - Compute Acceleration Framework; - ACPI drivers; - Serial ATA and Parallel ATA drivers; - ATM drivers; - Drivers core; - Power management core; - DRBD Distributed Replicated Block Device drivers; - Rados block device (RBD) driver; - RNBD block device driver; - Ublk userspace block driver; - Compressed RAM block device driver; - Bluetooth drivers; - Bus devices; - Character device driver; - TPM device driver; - Clock framework and drivers; - Clocksource drivers; - Data acquisition framework and drivers; - Counter interface drivers; - CPU frequency scaling framework; - CPU idle management framework; - Hardware crypto device drivers; - CXL (Compute Express Link) drivers; - DMA engine subsystem; - EDAC drivers; - EFI core; - GPIO subsystem; - GPU drivers; - Greybus drivers; - HID subsy

CSIRTS triage

What
A command starvation vulnerability in the libata-scsi layer where NCQ commands can block non-NCQ commands indefinitely, causing I/O hangs.
Who is affected
Systems using SATA/SAS controllers with NCQ support under heavy mixed workloads.
Urgency
Medium; CVSS 5.5 indicates denial-of-service risk but requires specific workload conditions.
Action
Update to a patched Linux kernel version with proper NCQ/non-NCQ command scheduling fairness in libata-scsi.

AI-assisted analysis generated from the source advisory — verify against the original.

⚡ Watch CVE-2026-45855

Get an email if CVE-2026-45855 is added to CISA KEV, gains public exploit code, or a new advisory cites it — max one per day, one-click unsubscribe.

Exploitation outlook

Advisory coverage (14)

External references

NVD record for CVE-2026-45855

CVE.org record

Embed the live status

CVE-2026-45855 live status badge — this badge updates automatically when the KEV or exploit status changes. How to embed it →

[![CVE-2026-45855 status](https://www.csirts.com/badge/CVE-2026-45855)](https://www.csirts.com/cve/CVE-2026-45855)