{"dataType":"CVE_RECORD","dataVersion":"5.2","cveMetadata":{"cveId":"CVE-2026-64051","assignerOrgId":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","state":"PUBLISHED","assignerShortName":"Linux","dateReserved":"2026-07-19T07:54:57.029Z","datePublished":"2026-07-19T15:39:34.608Z","dateUpdated":"2026-08-05T12:38:42.519Z"},"containers":{"cna":{"providerMetadata":{"orgId":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","shortName":"Linux","dateUpdated":"2026-08-05T12:38:42.519Z"},"descriptions":[{"lang":"en","value":"In the Linux kernel, the following vulnerability has been resolved:\n\naccel/qaic: Add overflow check to remap_pfn_range during mmap\n\nThe call to remap_pfn_range in qaic_gem_object_mmap is susceptible to\n(re)mapping beyond the VMA if the BO is too large. This can cause use\nafter free issues when munmap() unmaps only the VMA region and not the\nadditional mappings. To prevent this, check the remaining size of the\nVMA before remapping and truncate the remapped length if sg->length is\ntoo large.\n\n[jhugo: fix braces from checkpatch --strict]"}],"metrics":[{"cvssV3_1":{"version":"3.1","vectorString":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H","baseScore":7.8,"baseSeverity":"HIGH"},"scenarios":[{"lang":"en","value":"AV:L - Exploitation requires local access via the QAIC accel device node (/dev/accel/accel*) through DRM ioctls and mmap syscalls; there is no network-facing attack surface.\nAC:L - An attacker fully controls BO allocation size, partial mmap length, and munmap timing, deterministically mapping PFNs beyond the VMA without races or external conditions.\nPR:L - No DRM master or root is required; any unprivileged local user with access to the accel device node (common on shared cloud AI inference hosts) can create a BO, partial-mmap it, and trigger the bug.\nUI:N - Exploitation requires only attacker-initiated ioctl and mmap operations on an open accel file descriptor, with no victim interaction.\nS:U - The UAF corrupts kernel page-table mappings within the same kernel security domain; it does not cross VM, container, or IOMMU boundaries.\nC:H - The commit explicitly identifies a use-after-free of page structures left mapped past the VMA; UAF of kernel mappings enables arbitrary kernel memory read primitives.\nI:H - UAF on kernel page structures can be leveraged for arbitrary kernel memory writes and local privilege escalation through heap grooming and control of freed pages.\nA:H - Accessing stale PFN mappings after BO teardown causes kernel oops/panic; UAF reliably threatens system availability even before full exploitation."}]}],"affected":[{"product":"Linux","vendor":"Linux","defaultStatus":"unaffected","repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","programFiles":["drivers/accel/qaic/qaic_data.c"],"versions":[{"version":"ff13be8303336ead5621712f2c55012d738878b5","lessThan":"9baafc2fea096279e75480f93fd5942e8336b510","status":"affected","versionType":"git"},{"version":"ff13be8303336ead5621712f2c55012d738878b5","lessThan":"8dd6edbe26770df147136c3f2ac976c873b82650","status":"affected","versionType":"git"},{"version":"ff13be8303336ead5621712f2c55012d738878b5","lessThan":"97a8e89cdef36207a8776edc03d6931763a06ad0","status":"affected","versionType":"git"},{"version":"ff13be8303336ead5621712f2c55012d738878b5","lessThan":"8c795012d0e06b7740e40319b86ff8d2a435098d","status":"affected","versionType":"git"},{"version":"ff13be8303336ead5621712f2c55012d738878b5","lessThan":"aa16b2bc0f02709919e2435f531406531e5bcc69","status":"affected","versionType":"git"}]},{"product":"Linux","vendor":"Linux","defaultStatus":"affected","repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","programFiles":["drivers/accel/qaic/qaic_data.c"],"versions":[{"version":"6.4","status":"affected"},{"version":"0","lessThan":"6.4","status":"unaffected","versionType":"semver"},{"version":"6.6.142","lessThanOrEqual":"6.6.*","status":"unaffected","versionType":"semver"},{"version":"6.12.92","lessThanOrEqual":"6.12.*","status":"unaffected","versionType":"semver"},{"version":"6.18.34","lessThanOrEqual":"6.18.*","status":"unaffected","versionType":"semver"},{"version":"7.0.11","lessThanOrEqual":"7.0.*","status":"unaffected","versionType":"semver"},{"version":"7.1","lessThanOrEqual":"*","status":"unaffected","versionType":"original_commit_for_fix"}]}],"cpeApplicability":[{"nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*","versionStartIncluding":"6.4","versionEndExcluding":"6.6.142"},{"vulnerable":true,"criteria":"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*","versionStartIncluding":"6.4","versionEndExcluding":"6.12.92"},{"vulnerable":true,"criteria":"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*","versionStartIncluding":"6.4","versionEndExcluding":"6.18.34"},{"vulnerable":true,"criteria":"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*","versionStartIncluding":"6.4","versionEndExcluding":"7.0.11"},{"vulnerable":true,"criteria":"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*","versionStartIncluding":"6.4","versionEndExcluding":"7.1"}]}]}],"references":[{"url":"https://git.kernel.org/stable/c/9baafc2fea096279e75480f93fd5942e8336b510"},{"url":"https://git.kernel.org/stable/c/8dd6edbe26770df147136c3f2ac976c873b82650"},{"url":"https://git.kernel.org/stable/c/97a8e89cdef36207a8776edc03d6931763a06ad0"},{"url":"https://git.kernel.org/stable/c/8c795012d0e06b7740e40319b86ff8d2a435098d"},{"url":"https://git.kernel.org/stable/c/aa16b2bc0f02709919e2435f531406531e5bcc69"}],"title":"accel/qaic: Add overflow check to remap_pfn_range during mmap","x_generator":{"engine":"bippy-1.2.0"}}}}