Vulnerability in Linux Kernel Affecting Raspberry Pi 4
CVE-2026-64149

Currently unrated

Key Information:

Vendor

Linux

Status
Vendor
CVE Published:
19 July 2026

What is CVE-2026-64149?

A vulnerability has been identified in the Linux kernel relating to the dma_map_resource() function, which improperly uses pfn_valid() to validate memory ranges. This issue is particularly significant on ARM64 platforms with SPARSEMEM configuration, leading to potential warnings and mapping errors. Specifically, during the SPI BCM2835 probe on the Raspberry Pi 4, it can erroneously trigger warnings when memory-mapped I/O addresses share sections with RAM, resulting in incorrect DMA mapping behavior. A corrective measure has been implemented, ensuring that the sanity check accurately distinguishes usable RAM from MMIO regions, thereby enhancing the kernel’s integrity and operational reliability.

Affected Version(s)

Linux f7326196a781622b33bfbdabb00f5e72b5fb5679 < 181e67bc11c5ec5b87c6c512c2078752b23ca8d4

Linux f7326196a781622b33bfbdabb00f5e72b5fb5679 < 004a777879ff629f6e0ca3d09ad09fa3452bcc4d

Linux f7326196a781622b33bfbdabb00f5e72b5fb5679

References

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.