SB20260727121 - Heap-based buffer overflow in Linux kernel staging vme_user driver
Published: July 27, 2026
Breakdown by Severity
- Low
- Medium
- High
- Critical
Description
This security bulletin contains information about 1 vulnerability.
1) Heap-based buffer overflow (CVE-ID: CVE-2026-64449)
CWE-ID: CWE-122 - Heap-based Buffer Overflow
CVSSv4: CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:U/U:Clear
The vulnerability allows a local user to cause a denial of service or execute arbitrary code.
The vulnerability exists due to a heap-based buffer overflow in the SLAVE-path helpers buffer_to_user() and buffer_from_user() in drivers/staging/vme_user/vme_user.c when processing read and write operations with an offset and count that exceed the fixed kern_buf size. A local user can issue crafted read or write operations to cause a denial of service or execute arbitrary code.
The issue occurs when the configured slave window exceeds the 128 KiB kern_buf allocation.
Remediation
Install update from vendor's website.
References
- https://git.kernel.org/stable/c/1b495fa0d4927c88d88bf346bf311f2e26e860ed
- https://git.kernel.org/stable/c/65358d89dc9f1c25d9364b2b3ef0f3b47717f9ed
- https://git.kernel.org/stable/c/8eff7cd4817e14dbe3b9952cce55ef52d1d38940
- https://git.kernel.org/stable/c/9f32f38265014fac7f5dc9490fb01a638ce6e121
- https://git.kernel.org/stable/c/adc8b9c30d716c362646edb45662aa1c641a154a
- https://git.kernel.org/stable/c/e99f2df433c63c86c93de1e5f08f16e404388756