Power Management Flaw in Linux Kernel vfio/pci by Red Hat
CVE-2026-64476

Currently unrated

Key Information:

Vendor

Linux

Status
Vendor
CVE Published:
25 July 2026

What is CVE-2026-64476?

A vulnerability exists in the vfio/pci module of the Linux Kernel that can lead to unbalanced power management operations. The issue arises from the mismanagement of the disable_idle_d3 flag, which is intended to control device power states. Without proper reference counting and balanced operations, it becomes possible for devices bound to vfio-pci drivers to exhibit inconsistent behavior during power state transitions. This vulnerability can potentially lead to reliability issues within systems utilizing devices managed by the vfio-pci driver.

Affected Version(s)

Linux 7ab5e10eda02da1d9562ffde562c51055d368e9c < 332d785f9ae426eeeb92527872adf09d84101ba3

Linux 7ab5e10eda02da1d9562ffde562c51055d368e9c < 654710ef3135c4546b20a903bc23a51b0c44d6c8

Linux 7ab5e10eda02da1d9562ffde562c51055d368e9c

References

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.