Junglewise Threat Intelligence

CVE-2026-64039: Linux Kernel drm/msm memory alignment error in snapshot utility

CVE-2026-64039 · Severity: info · CVSS 0 · Published 2026-07-19

Technologies: Linux Kernel. Vendors: Linux.

Executive brief

A vulnerability was identified in the Linux kernel's display driver for Qualcomm MSM chipsets. The issue occurs when the system attempts to take a 'snapshot' of the display state for debugging, where it incorrectly handles memory alignment for certain data regions. This could lead to improper memory access or system instability during diagnostic procedures.

Technical details

A vulnerability in the drm/msm/snapshot component of the Linux kernel was caused by the snapshotting code internally aligning data segments to 16 bytes. While this worked for DPU code, it failed for DSI data regions which are shifted by 4 bytes, leading to inaccurate register dumps. Additionally, the msm_disp_state_dump_regs() function suffered from a 16x memory overallocation bug. The fix involves removing the rigid length alignment and accurately calculating the remaining registers in unaligned regions. This is primarily a local stability and correctness issue reachable during display state debugging.

Affected products

  • Linux Linux Kernel 5.14 to 5.15.209, 6.1.175, 6.6.142, 6.12.92

Timeline

  • 2026-05-16: disclosed: Initial patch submitted to patchwork
  • 2026-06-01: patched: Commits merged into stable branches
  • 2026-07-19: advisory: CVE published and NVD record created

References

Related threats