Junglewise Threat Intelligence

CVE-2026-89721: Linux kernel Rockchip Samsung DCPHY out-of-bounds memory access

CVE-2026-89721 · Severity: info · Published 2026-09-11

Technologies: Linux Kernel. Vendors: Linux.

Executive brief

The Linux kernel's Rockchip Samsung DCPHY PHY driver incorrectly configures its register address range, allowing debugfs register dump operations to read beyond allocated memory. This causes a kernel panic (oops) with the regmap lock held, resulting in deadlock of all subsequent PHY operations and system instability.

Technical details

The vulnerability is an out-of-bounds memory access in the Rockchip Samsung DCPHY driver's regmap configuration. The PHY register block is 64KB with a 4-byte register stride, making the last valid register offset 0xfffc, but max_register was incorrectly set to 0x10000 (one register past the end). When users dump registers via the regmap debugfs interface, the code attempts to read from this invalid offset, triggering an oops on the unmapped memory page. The oops occurs while holding the regmap lock, causing subsequent PHY operations to deadlock. The fix changes max_register from 0x10000 to 0xfffc. No authentication is required; local access to debugfs is sufficient to trigger the issue.

Affected products

  • Linux Linux kernel multiple versions with phy: rockchip-samsung-dcphy driver

Timeline

  • 2026-09-11: disclosed
  • 2026-08-11: patched

References

Related threats