Executive brief
A vulnerability was identified in the Linux kernel's Qualcomm USB-C driver. This issue could allow an out-of-bounds memory access when configuring DisplayPort settings on certain Qualcomm-based hardware. While primarily a technical stability issue, such flaws can potentially lead to system crashes or unpredictable behavior in the operating system.
Technical details
An out-of-bounds array access vulnerability exists in the 'qmp_v2_configure_dp_swing' function within 'drivers/phy/qualcomm/phy-qcom-qmp-usbc.c'. The 'swing_tbl' and 'pre_emphasis_tbl' are 4x4 arrays, meaning valid indices are 0-3. However, the boundary check incorrectly used a 'greater than 4' condition instead of 'greater than or equal to 4', allowing an index of 4 to bypass the check and access memory outside the array bounds. This issue affects Qualcomm QCS615 USB/DP PHY configurations. Patches have been released for the stable kernel branches to correct the logic to '>= 4'.
Affected products
- Linux Linux Kernel 7.0 to 7.0.11
Timeline
- 2026-07-24: disclosed
- 2026-07-24: advisory