๐Ÿ” CVE Alert

CVE-2026-64280

UNKNOWN 0.0

fpga: dfl-afu: validate DMA mapping length in afu_dma_map_region()

CVSS Score
0.0
EPSS Score
0.0%
EPSS Percentile
0th

In the Linux kernel, the following vulnerability has been resolved: fpga: dfl-afu: validate DMA mapping length in afu_dma_map_region() afu_ioctl_dma_map() accepts a 64-bit length from userspace via DFL_FPGA_PORT_DMA_MAP ioctl without an upper bound check. The value is passed to afu_dma_pin_pages() where npages is derived as length >> PAGE_SHIFT and passed to pin_user_pages_fast() which takes int nr_pages, causing implicit truncation if length is very large. Validate map.length at the ioctl entry point before calling afu_dma_map_region(), rejecting values whose page count exceeds INT_MAX.

Vendor linux
Product linux
Ecosystems
Industries
Technology
Published Jul 25, 2026
Stay Ahead of the Next One

Get instant alerts for linux linux

Be the first to know when new unknown vulnerabilities affecting linux linux are published โ€” delivered to Slack, Telegram or Discord.

Get Free Alerts โ†’ Free ยท No credit card ยท 60 sec setup

Affected Versions

Linux / Linux
fa8dda1edef9ebc3af467c644c5533ac97171e12 < 59070040fd12e0b78d7b4d341d9f9a183237c5ff fa8dda1edef9ebc3af467c644c5533ac97171e12 < fb2c0eab51ae5b02d2bae7d67c2cfbec39b57231 fa8dda1edef9ebc3af467c644c5533ac97171e12 < fc3b071a7c8dc0f5d56defddf6e6fd5aaa3e1e27
Linux / Linux
4.19

References

NVD โ†— CVE.org โ†— EPSS Data โ†—
git.kernel.org: https://git.kernel.org/stable/c/59070040fd12e0b78d7b4d341d9f9a183237c5ff git.kernel.org: https://git.kernel.org/stable/c/fb2c0eab51ae5b02d2bae7d67c2cfbec39b57231 git.kernel.org: https://git.kernel.org/stable/c/fc3b071a7c8dc0f5d56defddf6e6fd5aaa3e1e27