CVE-2026-64219 Details
Description
In the Linux kernel, the following vulnerability has been resolved: drm/amd/display: Validate payload length and link_index in dc_process_dmub_aux_transfer_async [Why&How] dc_process_dmub_aux_transfer_async() copies payload->length bytes into a 16-byte stack buffer (dpaux.data[16]) guarded only by an ASSERT(), which is a no-op in release builds. If a caller ever passes length > 16 this results in a stack buffer overflow via memcpy. Additionally, link_index is used to dereference dc->links[] without bounds checking against dc->link_count, risking an out-of-bounds access. Replace the ASSERT with a hard runtime check that returns false when payload->length exceeds the destination buffer size, and add a bounds check for link_index before it is used. (cherry picked from commit ba4caa9fecdf7a38f98c878ad05a8a64148b6881)
A stack buffer overflow vulnerability has been identified in the Linux kernel's AMD display driver. The issue arises in the 'dc_process_dmub_aux_transfer_async' function, where the payload length is not properly validated before being copied into a 16-byte stack buffer. This flaw allows for a buffer overflow if the payload length exceeds 16 bytes. Additionally, the vulnerability includes a risk of out-of-bounds access, as the 'link_index' is used to reference an array without adequate bounds checking.
The vulnerability has been addressed by replacing the assertion that allowed arbitrary lengths with a proper runtime check that ensures the length does not exceed the buffer size. This fix is available in the Linux kernel stable tree.
Metrics
CVSS 4.0 Severity and Vector Strings:
No CVSS 4.0 data is available for this CVE.
CVSS 3.x Severity and Vector Strings:
No data available for CVSS Version 2.0 on this CVE.
No SSVC data is available for this CVE.
References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.
| URL | Source(s) | Tag(s) |
|---|---|---|
| https://git.kernel.org/stable/c/16a5fa57565afb6bf37e18129921c270c93d8e2b | kernel.org | Patch |
| https://git.kernel.org/stable/c/1c8c6e912f2945b2a3e669afca6b52174b88e86e | kernel.org | Patch |
| https://git.kernel.org/stable/c/1ecde19bfce6535bffddad1139ff466b6d401b8e | kernel.org | Patch |
| https://git.kernel.org/stable/c/3265f3ed373fb8048be713aadcdf702579a0e53d | kernel.org | Patch |
| https://git.kernel.org/stable/c/6c92f6d9600efa3ef0d9e560a2b52776d9803c29 | kernel.org | Patch |
| https://git.kernel.org/stable/c/90c398e822ca76e40548df0c061dd4f93ea92d71 | kernel.org | Patch |
| https://git.kernel.org/stable/c/d6590e3f766e3111dd1beaf88b9384d117acfa6b | kernel.org | Patch |
Weakness Enumeration
| CWE-ID | CWE Name | Source |
|---|---|---|
| CWE-674 | Uncontrolled Recursion | [email protected] |
Affected Products
| Product | Versions |
|---|---|
| linux linux kernel | >= 5.13, < 5.15.209 >= 5.16, < 6.1.175 >= 6.2, < 6.6.142 >= 6.7, < 6.12.92 >= 6.13, < 6.18.34 >= 6.19, < 7.0.11 7.1 rc1 7.1 rc2 7.1 rc3 7.1 rc4 |
CPE
Remediation
| |
Change History
3 change records found show changes
| Date | Action | Recorded By |
|---|---|---|
| Aug 11, 2026 | Initial Analysis | [email protected] |
| Jul 27, 2026 | CVE Modified | kernel.org |
| Jul 24, 2026 | New CVE Received | kernel.org |