CVE-2026-64049

Summary

In the Linux kernel, the following vulnerability has been resolved:

drm/msm/adreno: fix userspace-triggered crash on a2xx-a4xx

Before a5xx Adreno driver will not try fetching UBWC params (because those generations didn't support UBWC anyway), however it's still possible to query UBWC-related params from the userspace, triggering possible NULL pointer dereference. Check for UBWC config in adreno_get_param() and return sane defaults if there is none.

Patchwork: https://patchwork.freedesktop.org/patch/717778/

Affected Software

VendorProductVersion RangeStatus
LinuxLinuxa452510aad53f665eb422784ff525c4889aa246f < eea43d5ed45089705bc5d70971c39076962d5951affected
LinuxLinuxa452510aad53f665eb422784ff525c4889aa246f < 22fc33d9b67694b24e0deb3f08c622464338cecbaffected
LinuxLinuxa452510aad53f665eb422784ff525c4889aa246f < 2b4abf879360ea00a9e2b46d2d15dcdbc0687eedaffected
LinuxLinux6.17affected
LinuxLinux0 < 6.17unaffected
LinuxLinux6.18.34 <= 6.18.*unaffected
LinuxLinux7.0.11 <= 7.0.*unaffected
LinuxLinux7.1 <= *unaffected

Weaknesses

References