Junglewise Threat Intelligence

CVE-2026-64049: Linux Kernel NULL pointer dereference in Adreno GPU driver

CVE-2026-64049 · Severity: info · CVSS 5.5 · Published 2026-07-19

Technologies: Linux. Vendors: Linux.

Executive brief

A vulnerability in the Linux kernel's Adreno graphics driver could allow a local user to crash the system. This affects older hardware generations (a2xx-a4xx) that do not support certain modern compression features. An exploit would result in a denial-of-service, potentially disrupting operations or causing data loss for unsaved work.

Technical details

A NULL pointer dereference exists in the adreno_get_param() function within drivers/gpu/drm/msm/adreno/adreno_gpu.c. On Adreno a2xx through a4xx generations, the driver does not initialize Universal Bandwidth Compression (UBWC) parameters because the hardware does not support them. However, the driver failed to validate the existence of the UBWC configuration before attempting to fulfill userspace queries for UBWC-related parameters (MSM_PARAM_HIGHEST_BANK_BIT, MSM_PARAM_UBWC_SWIZZLE, and MSM_PARAM_MACROTILE_MODE). A local attacker can trigger this dereference by querying these parameters, leading to a kernel oops and system crash. The issue has been patched by adding checks for the ubwc_config pointer in adreno_get_param().

Affected products

  • Linux Linux 6.17 to 6.18.33, 7.0 to 7.0.10

Timeline

  • 2026-07-19: disclosed
  • 2026-07-19: advisory

References