Out-of-Bounds Access in Linux Kernel Affecting Qualcomm QMP USB-C
CVE-2026-64209

Currently unrated

Key Information:

Vendor

Linux

Status
Vendor
CVE Published:
24 July 2026

What is CVE-2026-64209?

A vulnerability identified within the Linux kernel involves an out-of-bounds array access in the Qualcomm QMP USB-C driver. Specifically, the issue arises in the configuration of the DP swing settings where boundary checks are incorrectly set, allowing for potential out-of-bounds access when utilizing the swing_tbl and pre_emphasis_tbl arrays, which are designed to be accessed with valid indices ranging from 0 to 3. This flaw could lead to unforeseen behavior or security issues, necessitating immediate attention for those using affected kernel versions.

Affected Version(s)

Linux 81791c45c8e0eaeba9a40927eecd082a8500f709

Linux 81791c45c8e0eaeba9a40927eecd082a8500f709

Linux 7.0

References

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.