CVE-2026-64334
Low
No strong exploitation signal.
CVSS base
5.5
MEDIUM
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
EPSS — probability of exploitation (30 days)
0.1%
0.7th percentile
CISA KEV
Not listed
Weakness / dates
CWE-667
Published 2026-07-25 · modified 2026-09-03
CVSS breakdown
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
| Attack Vector | L | Local |
| Attack Complexity | L | Low |
| Privileges Required | L | Low |
| User Interaction | N | None |
| Scope | U | Unchanged |
| Confidentiality | N | None |
| Integrity | N | None |
| Availability | H | High |
Timeline
- 2026-07-25 — Published (NVD)
- 2026-09-03 — Last modified (NVD)
Description
In the Linux kernel, the following vulnerability has been resolved: USB: serial: digi_acceleport: fix hard lockup on disconnect If submitting the OOB write urb fails persistently (e.g if the device is being disconnected) the driver would loop indefinitely with interrupts disabled. Check for urb submission errors when sending OOB commands to avoid hanging if, for example, open(), set_termios() or close() races with a physical disconnect. This is issue was flagged by Sashiko when reviewing an unrelated change to the driver.
Affected
References
- https://git.kernel.org/stable/c/2067b3838da6e4af03bae3630414193188d754b2
- https://git.kernel.org/stable/c/2b7dc482f859f2d027db07ff0efc1c5df5b3451a
- https://git.kernel.org/stable/c/5a82d842e8c35227d7227f19e5e654df1451782c
- https://git.kernel.org/stable/c/5c1ea24b53bf3bfb859f0a05573997487975da23
- https://git.kernel.org/stable/c/6a8592ace932081ea11aea41c460a1ca0f6344a4
- https://git.kernel.org/stable/c/6e51147c2744d15730084dc89cc99180d3de4184
- https://git.kernel.org/stable/c/79bc131df0e50f8f663c1fdbbe952aaf193a8d39
- https://git.kernel.org/stable/c/bcfeae431db9986c2b313e6a760f2ac8df61e138