Out-of-bounds read in Linux kernel - CVE-2026-64231
Published: July 27, 2026
Vulnerability details
The vulnerability allows a local user to cause a denial of service.
The vulnerability exists due to an out-of-bounds read in msm_disp_snapshot_add_block when dumping DSI host registers after the IO base address is adjusted by io_offset. A local user can trigger register dumping to cause a denial of service.
The issue affects DSI 6G platforms.
Affected software
Ubuntu
linux (Ubuntu package)
linux-aws (Ubuntu package)
linux-gcp-7.0 (Ubuntu package)
linux-nvidia (Ubuntu package)
linux-nvidia-bos (Ubuntu package)
How to mitigate CVE-2026-64231
linux (Ubuntu package) - addressed in versions 6.8.0-139.139+fips1, 6.8.0-1049.53, 6.8.0-1062.65+fips1, 6.8.0-1062.65.1, 6.8.0-1062.65~22.04.1, 6.8.0-1062.70, 6.8.0-1064.68, 6.8.0-1067.75, 6.8.0-1067.75+fips1, 6.8.1-1059.60, 6.8.1-1059.60~22.04.1
linux-aws (Ubuntu package) - addressed in versions 7.0.0-1009.9, 7.0.0-1015.15
linux-gcp-7.0 (Ubuntu package) - update to 7.0.0-1011.11~24.04.1
linux-nvidia (Ubuntu package) - addressed in versions 7.0.0-1016.16, 7.0.0-1016.16~24.04.1
linux-nvidia-bos (Ubuntu package) - update to 7.0.0-2016.16
External References
- https://git.kernel.org/stable/c/567b5e976e2e15280d78c9ef2add1954a0bbb5b1
- https://git.kernel.org/stable/c/5b49a46baa853b26dbefa65c6c75dd9ff69f63d4
- https://git.kernel.org/stable/c/5e2c196c3430fb94225c4102b1028d0146544761
- https://git.kernel.org/stable/c/9f8274749d9010a1a72f97e547b7eb9ebb82345b
- https://git.kernel.org/stable/c/a184aec790135938b0fadb415e55accd1f8685a0
- https://git.kernel.org/stable/c/ab871d5882953e5574ae2bc47bec88c2e3d22663