Out-of-bounds read in Linux kernel - CVE-2026-64039
Published: July 20, 2026
Linux kernel
Detailed vulnerability description
The vulnerability allows a local user to cause a denial of service.
The vulnerability exists due to an out-of-bounds read in msm_disp_state_print_regs and related snapshot dumping logic when processing unaligned DSI register regions. A local user can trigger snapshotting of a specially positioned unaligned region to cause a denial of service.
The issue occurs because some DSI data regions are shifted by 4 bytes, causing the last registers in the region to be handled incorrectly.
How to mitigate CVE-2026-64039
Sources
- https://git.kernel.org/stable/c/070e40acc59ef7bedba0314f59971ba87fcc8ab0
- https://git.kernel.org/stable/c/0c90ececfad3fc5c4c43a75ece0e2d736ab3def1
- https://git.kernel.org/stable/c/1ef79be774706dddcfcace0331fa7ff32a73c73e
- https://git.kernel.org/stable/c/76824d2467feb1828b745d6add2541918d7be3da
- https://git.kernel.org/stable/c/8fb070cf95847b29ef6cb15ec2c0de2bf4704676
- https://git.kernel.org/stable/c/cdd1aaf0ee962f50810b9aef7928f2313989d55f
- https://git.kernel.org/stable/c/cecd34e046121d788a70b5c8b4f8a88916637953