CVE-2026-64051 (GCVE-0-2026-64051)
Vulnerability from cvelistv5
Published
2026-07-19 15:39
Modified
2026-08-05 12:38
Summary
In the Linux kernel, the following vulnerability has been resolved: accel/qaic: Add overflow check to remap_pfn_range during mmap The call to remap_pfn_range in qaic_gem_object_mmap is susceptible to (re)mapping beyond the VMA if the BO is too large. This can cause use after free issues when munmap() unmaps only the VMA region and not the additional mappings. To prevent this, check the remaining size of the VMA before remapping and truncate the remapped length if sg->length is too large. [jhugo: fix braces from checkpatch --strict]
Impacted products
Vendor Product Version
Linux Linux Version: ff13be8303336ead5621712f2c55012d738878b5
Version: ff13be8303336ead5621712f2c55012d738878b5
Version: ff13be8303336ead5621712f2c55012d738878b5
Version: ff13be8303336ead5621712f2c55012d738878b5
Version: ff13be8303336ead5621712f2c55012d738878b5
Create a notification for this product.
Show details on NVD website


{
  "containers": {
    "cna": {
      "affected": [
        {
          "defaultStatus": "unaffected",
          "product": "Linux",
          "programFiles": [
            "drivers/accel/qaic/qaic_data.c"
          ],
          "repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
          "vendor": "Linux",
          "versions": [
            {
              "lessThan": "9baafc2fea096279e75480f93fd5942e8336b510",
              "status": "affected",
              "version": "ff13be8303336ead5621712f2c55012d738878b5",
              "versionType": "git"
            },
            {
              "lessThan": "8dd6edbe26770df147136c3f2ac976c873b82650",
              "status": "affected",
              "version": "ff13be8303336ead5621712f2c55012d738878b5",
              "versionType": "git"
            },
            {
              "lessThan": "97a8e89cdef36207a8776edc03d6931763a06ad0",
              "status": "affected",
              "version": "ff13be8303336ead5621712f2c55012d738878b5",
              "versionType": "git"
            },
            {
              "lessThan": "8c795012d0e06b7740e40319b86ff8d2a435098d",
              "status": "affected",
              "version": "ff13be8303336ead5621712f2c55012d738878b5",
              "versionType": "git"
            },
            {
              "lessThan": "aa16b2bc0f02709919e2435f531406531e5bcc69",
              "status": "affected",
              "version": "ff13be8303336ead5621712f2c55012d738878b5",
              "versionType": "git"
            }
          ]
        },
        {
          "defaultStatus": "affected",
          "product": "Linux",
          "programFiles": [
            "drivers/accel/qaic/qaic_data.c"
          ],
          "repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
          "vendor": "Linux",
          "versions": [
            {
              "status": "affected",
              "version": "6.4"
            },
            {
              "lessThan": "6.4",
              "status": "unaffected",
              "version": "0",
              "versionType": "semver"
            },
            {
              "lessThanOrEqual": "6.6.*",
              "status": "unaffected",
              "version": "6.6.142",
              "versionType": "semver"
            },
            {
              "lessThanOrEqual": "6.12.*",
              "status": "unaffected",
              "version": "6.12.92",
              "versionType": "semver"
            },
            {
              "lessThanOrEqual": "6.18.*",
              "status": "unaffected",
              "version": "6.18.34",
              "versionType": "semver"
            },
            {
              "lessThanOrEqual": "7.0.*",
              "status": "unaffected",
              "version": "7.0.11",
              "versionType": "semver"
            },
            {
              "lessThanOrEqual": "*",
              "status": "unaffected",
              "version": "7.1",
              "versionType": "original_commit_for_fix"
            }
          ]
        }
      ],
      "cpeApplicability": [
        {
          "nodes": [
            {
              "cpeMatch": [
                {
                  "criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
                  "versionEndExcluding": "6.6.142",
                  "versionStartIncluding": "6.4",
                  "vulnerable": true
                },
                {
                  "criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
                  "versionEndExcluding": "6.12.92",
                  "versionStartIncluding": "6.4",
                  "vulnerable": true
                },
                {
                  "criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
                  "versionEndExcluding": "6.18.34",
                  "versionStartIncluding": "6.4",
                  "vulnerable": true
                },
                {
                  "criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
                  "versionEndExcluding": "7.0.11",
                  "versionStartIncluding": "6.4",
                  "vulnerable": true
                },
                {
                  "criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
                  "versionEndExcluding": "7.1",
                  "versionStartIncluding": "6.4",
                  "vulnerable": true
                }
              ],
              "negate": false,
              "operator": "OR"
            }
          ]
        }
      ],
      "descriptions": [
        {
          "lang": "en",
          "value": "In the Linux kernel, the following vulnerability has been resolved:\n\naccel/qaic: Add overflow check to remap_pfn_range during mmap\n\nThe call to remap_pfn_range in qaic_gem_object_mmap is susceptible to\n(re)mapping beyond the VMA if the BO is too large. This can cause use\nafter free issues when munmap() unmaps only the VMA region and not the\nadditional mappings. To prevent this, check the remaining size of the\nVMA before remapping and truncate the remapped length if sg-\u003elength is\ntoo large.\n\n[jhugo: fix braces from checkpatch --strict]"
        }
      ],
      "metrics": [
        {
          "cvssV3_1": {
            "baseScore": 7.8,
            "baseSeverity": "HIGH",
            "vectorString": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H",
            "version": "3.1"
          },
          "scenarios": [
            {
              "lang": "en",
              "value": "AV:L - Exploitation requires local access via the QAIC accel device node (/dev/accel/accel*) through DRM ioctls and mmap syscalls; there is no network-facing attack surface.\nAC:L - An attacker fully controls BO allocation size, partial mmap length, and munmap timing, deterministically mapping PFNs beyond the VMA without races or external conditions.\nPR:L - No DRM master or root is required; any unprivileged local user with access to the accel device node (common on shared cloud AI inference hosts) can create a BO, partial-mmap it, and trigger the bug.\nUI:N - Exploitation requires only attacker-initiated ioctl and mmap operations on an open accel file descriptor, with no victim interaction.\nS:U - The UAF corrupts kernel page-table mappings within the same kernel security domain; it does not cross VM, container, or IOMMU boundaries.\nC:H - The commit explicitly identifies a use-after-free of page structures left mapped past the VMA; UAF of kernel mappings enables arbitrary kernel memory read primitives.\nI:H - UAF on kernel page structures can be leveraged for arbitrary kernel memory writes and local privilege escalation through heap grooming and control of freed pages.\nA:H - Accessing stale PFN mappings after BO teardown causes kernel oops/panic; UAF reliably threatens system availability even before full exploitation."
            }
          ]
        }
      ],
      "providerMetadata": {
        "dateUpdated": "2026-08-05T12:38:42.519Z",
        "orgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
        "shortName": "Linux"
      },
      "references": [
        {
          "url": "https://git.kernel.org/stable/c/9baafc2fea096279e75480f93fd5942e8336b510"
        },
        {
          "url": "https://git.kernel.org/stable/c/8dd6edbe26770df147136c3f2ac976c873b82650"
        },
        {
          "url": "https://git.kernel.org/stable/c/97a8e89cdef36207a8776edc03d6931763a06ad0"
        },
        {
          "url": "https://git.kernel.org/stable/c/8c795012d0e06b7740e40319b86ff8d2a435098d"
        },
        {
          "url": "https://git.kernel.org/stable/c/aa16b2bc0f02709919e2435f531406531e5bcc69"
        }
      ],
      "title": "accel/qaic: Add overflow check to remap_pfn_range during mmap",
      "x_generator": {
        "engine": "bippy-1.2.0"
      }
    }
  },
  "cveMetadata": {
    "assignerOrgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
    "assignerShortName": "Linux",
    "cveId": "CVE-2026-64051",
    "datePublished": "2026-07-19T15:39:34.608Z",
    "dateReserved": "2026-07-19T07:54:57.029Z",
    "dateUpdated": "2026-08-05T12:38:42.519Z",
    "state": "PUBLISHED"
  },
  "dataType": "CVE_RECORD",
  "dataVersion": "5.2"
}


Log in or create an account to share your comment.




Tags
Taxonomy of the tags.


Loading…

Loading…

Loading…

Sightings

Author Source Type Date

Nomenclature

  • Seen: The vulnerability was mentioned, discussed, or seen somewhere by the user.
  • Confirmed: The vulnerability is confirmed from an analyst perspective.
  • Published Proof of Concept: A public proof of concept is available for this vulnerability.
  • Exploited: This vulnerability was exploited and seen by the user reporting the sighting.
  • Patched: This vulnerability was successfully patched by the user reporting the sighting.
  • Not exploited: This vulnerability was not exploited or seen by the user reporting the sighting.
  • Not confirmed: The user expresses doubt about the veracity of the vulnerability.
  • Not patched: This vulnerability was not successfully patched by the user reporting the sighting.


Loading…

Loading…