Junglewise Threat Intelligence

CVE-2026-64042: Linux Kernel missing BAR resource check in VFIO PCI DMABUF export

CVE-2026-64042 · Severity: info · CVSS 0 · Published 2026-07-19

Technologies: Linux Kernel. Vendors: Linux.

Executive brief

A vulnerability was identified in the Linux kernel's VFIO PCI driver, which is used to give virtual machines or user-space applications direct access to hardware devices. The system failed to properly verify that hardware memory regions were correctly reserved before sharing them. This could potentially allow an attacker to access sensitive system resources that should have remained protected, leading to unauthorized data access or system instability.

Technical details

A vulnerability in the Linux kernel's vfio/pci implementation arises from a lack of resource validation in the DMABUF export path. Specifically, the `vfio_pci_core_feature_dma_buf` function exported access to Base Address Register (BAR) resources without ensuring they were successfully claimed/reserved during startup. An attacker with sufficient privileges to interact with VFIO could potentially access unreserved or unintended memory regions through the exported DMABUF. The fix introduces a call to `vfio_pci_core_setup_barmap` within the DMABUF creation path to verify resource ownership before export. This issue affects versions starting from the introduction of DMABUF export support for MMIO regions (commit 5d74781ebc86c).

Affected products

  • Linux Linux Kernel 6.19, 7.0.11, 7.1

Timeline

  • 2026-05-11: disclosed: Initial patch submission by Matt Evans
  • 2026-07-19: advisory: CVE published in NVD dataset
  • 2026-07-19: patched: Fixes merged into stable branches 702809d and 8443cd4

References

Related threats