CVE-2026-64042
8.8
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H
Summary
In the Linux kernel, the following vulnerability has been resolved:
vfio/pci: Check BAR resources before exporting a DMABUF
A DMABUF exports access to BAR resources and, although they are requested at startup time, we need to ensure they really were reserved before exporting. Otherwise, it's possible to access unreserved resources through the export.
Add a check to the DMABUF-creation path.
Affected Software
| Vendor | Product | Version Range | Status |
|---|---|---|---|
| Linux | Linux | 5d74781ebc86c5fa9e9d6934024c505412de9b52 < 8443cd4497a4498c4b01058d76a92116244cb605 | affected |
| Linux | Linux | 5d74781ebc86c5fa9e9d6934024c505412de9b52 < 702809dabdecca807bdd50cfdcc1c980feb2ba62 | affected |
| Linux | Linux | 6.19 | affected |
| Linux | Linux | 0 < 6.19 | unaffected |
| Linux | Linux | 7.0.11 <= 7.0.* | unaffected |
| Linux | Linux | 7.1 <= * | unaffected |
Weaknesses
References
- https://git.kernel.org/stable/c/8443cd4497a4498c4b01058d76a92116244cb605
- https://git.kernel.org/stable/c/702809dabdecca807bdd50cfdcc1c980feb2ba62
Feedback
Was this page helpful?
Glad to hear it! Please tell us how we can improve.
Sorry to hear that. Please tell us how we can improve.