CSIRTS // UNIFIED SECURITY ADVISORY FEEDSYS ● ONLINE · POWERED BY INTELFUSIONS.COM

CVE-2026-64475

highCVSS 8.8covered by 2 sourcesfirst seen 2026-07-14
In the Linux kernel, the following vulnerability has been resolved: vfio/pci: Release the VGA arbiter client on register_device() failure The re-order in the Fixes commit below displaced vfio_pci_vga_init() as the last failure point of what is now vfio_pci_core_register_device() without introducing an unwind for the VGA arbiter registration. In current kernels this is mostly benign because vfio_pci_set_decode() only uses pci_dev state, but the original failure path could leave a callback with a freed vdev cookie. The stale registration also becomes unsafe again once the callback follows drvdata to the vfio device. Add the required VGA unwind callout.

CSIRTS triage

Other
What
The VGA arbiter client is not released on register_device() failure.
Who is affected
Deployments using vfio/pci.
Urgency
Remediation is necessary to prevent resource leaks.
Action
Apply the relevant patches once available.

AI-assisted analysis generated from the source advisory — verify against the original.

⚡ Watch CVE-2026-64475

Get an email if CVE-2026-64475 is added to CISA KEV, gains public exploit code, or a new advisory cites it — max one per day, one-click unsubscribe.

Exploitation outlook

Advisory coverage (2)

External references

NVD record for CVE-2026-64475

CVE.org record

Embed the live status

CVE-2026-64475 live status badge — this badge updates automatically when the KEV or exploit status changes. How to embed it →

[![CVE-2026-64475 status](https://www.csirts.com/badge/CVE-2026-64475)](https://www.csirts.com/cve/CVE-2026-64475)