Junglewise Threat Intelligence

CVE-2026-64051: Linux Kernel QAIC driver use-after-free in qaic_gem_object_mmap

CVE-2026-64051 · Severity: info · Published 2026-07-19

Technologies: Linux Kernel. Vendors: Linux.

Executive brief

A vulnerability was identified in the Linux kernel's Qualcomm Cloud AI (QAIC) accelerator driver. This component manages specialized hardware used for AI processing. An error in how the driver maps memory could allow a local attacker to cause a system crash or potentially access memory they should not have permission to see, leading to a 'use-after-free' condition.

Technical details

A vulnerability in the 'qaic_gem_object_mmap' function within 'drivers/accel/qaic/qaic_data.c' occurs because 'remap_pfn_range' does not sufficiently validate the size of the Buffer Object (BO) against the Virtual Memory Area (VMA). If the BO is larger than the VMA, the driver may create mappings beyond the intended VMA boundary. When 'munmap()' is subsequently called, it only unmaps the VMA region, leaving the additional mappings active. This results in a use-after-free scenario. The fix introduces overflow checks using 'check_add_overflow' and truncates the remapped length to ensure it fits within the VMA bounds. This issue affects Linux kernel versions starting from 6.4 (where the datapath was introduced) up to various stable branches (6.6.y, 6.12.y, 6.18.y, 7.0.y).

Affected products

  • Linux Linux Kernel 6.4 to 7.0.11

Timeline

  • 2026-04-30: other: Patch authored by Zack McKevitt
  • 2026-07-19: disclosed: CVE published and NVD record created

References

Related threats