CVE-2026-64051
Severity CVSS v4.0:
Pending analysis
Type:
Unavailable / Other
Publication date:
19/07/2026
Last modified:
30/07/2026
Description
In the Linux kernel, the following vulnerability has been resolved:<br />
<br />
accel/qaic: Add overflow check to remap_pfn_range during mmap<br />
<br />
The call to remap_pfn_range in qaic_gem_object_mmap is susceptible to<br />
(re)mapping beyond the VMA if the BO is too large. This can cause use<br />
after free issues when munmap() unmaps only the VMA region and not the<br />
additional mappings. To prevent this, check the remaining size of the<br />
VMA before remapping and truncate the remapped length if sg->length is<br />
too large.<br />
<br />
[jhugo: fix braces from checkpatch --strict]
Impact
Base Score 3.x
7.80
Severity 3.x
HIGH
References to Advisories, Solutions, and Tools
- https://git.kernel.org/stable/c/8c795012d0e06b7740e40319b86ff8d2a435098d
- https://git.kernel.org/stable/c/8dd6edbe26770df147136c3f2ac976c873b82650
- https://git.kernel.org/stable/c/97a8e89cdef36207a8776edc03d6931763a06ad0
- https://git.kernel.org/stable/c/9baafc2fea096279e75480f93fd5942e8336b510
- https://git.kernel.org/stable/c/aa16b2bc0f02709919e2435f531406531e5bcc69



