Back to overview

CVE-2026-64042

HIGH
8.8
CVSS 3.1
Description
In the Linux kernel, the following vulnerability has been resolved: vfio/pci: Check BAR resources before exporting a DMABUF A DMABUF exports access to BAR resources and, although they are requested at startup time, we need to ensure they really were reserved before exporting. Otherwise, it's possible to access unreserved resources through the export. Add a check to the DMABUF-creation path.

Metadata

CVE ID
CVE-2026-64042
State
PUBLISHED
Assigner
Linux
Reserved
2026-07-19 07:54 UTC
Published
2026-07-19 15:39 UTC
Last updated
2026-07-20 13:42 UTC
Vendor / Product
Linux / Linux
Sources
cve.org  ·  NVD

Severity & Metrics

8.8 HIGH CVSS 3.1
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H
Affected products (2)
VendorProductPlatformVersions
Linux Linux 5d74781ebc86c5fa9e9d6934024c505412de9b52 < 8443cd4497a4498c4b01058d76a92116244cb605, 5d74781ebc86c5fa9e9d6934024c505412de9b52 < 702809dabdecca807bdd50cfdcc1c980feb2ba62
Linux Linux 6.19, 0 < 6.19, 7.0.11 ≤ 7.0.*, 7.1 ≤ *
CVSS scores (1)
ScoreSeverityVersionSourceVector
8.8 HIGH 3.1 cna CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H
Back to overview