In the Linux kernel, the following vulnerability has been resolved: accel/qaic: Add overflow check to remap_pfn_range during mmap The call to… (CVE-2026-64051)
In the Linux kernel, the following vulnerability has been resolved: accel/qaic: Add overflow check to remap_pfn_range during mmap The call to remap_pfn_range in qaic_gem_object_mmap is susceptible to (re)mapping beyond the VMA if the BO is too large. This can cause use after free issues when munmap() unmaps only the VMA region and not the additional mappings. To prevent this, check the remaining size of the VMA before remapping and truncate the remapped length if sg->length is too large. [jhugo: fix braces from checkpatch --strict]
AI Analysis
Technical Summary
The Linux kernel's accel/qaic driver had a vulnerability where the remap_pfn_range call in qaic_gem_object_mmap could remap memory beyond the bounds of the VMA if the buffer object was oversized. This could lead to use-after-free issues because munmap() would unmap only the VMA region, leaving additional mappings intact and potentially accessible. The vulnerability was addressed by adding an overflow check to ensure the remapped length does not exceed the VMA size, truncating it if sg->length is too large.
Potential Impact
The vulnerability could cause use-after-free conditions in kernel memory management related to mmap operations in the accel/qaic driver. This may lead to memory corruption or stability issues in affected systems. No known exploits in the wild have been reported.
Mitigation Recommendations
A fix has been implemented in the Linux kernel by adding an overflow check to remap_pfn_range during mmap in the accel/qaic driver. Users should apply the official kernel updates that include this fix. Patch status is not explicitly confirmed in the provided data; therefore, check the vendor or Linux kernel advisory for the current remediation guidance.
In the Linux kernel, the following vulnerability has been resolved: accel/qaic: Add overflow check to remap_pfn_range during mmap The call to… (CVE-2026-64051)
Description
In the Linux kernel, the following vulnerability has been resolved: accel/qaic: Add overflow check to remap_pfn_range during mmap The call to remap_pfn_range in qaic_gem_object_mmap is susceptible to (re)mapping beyond the VMA if the BO is too large. This can cause use after free issues when munmap() unmaps only the VMA region and not the additional mappings. To prevent this, check the remaining size of the VMA before remapping and truncate the remapped length if sg->length is too large. [jhugo: fix braces from checkpatch --strict]
CVSS v3.1
AI-Powered Analysis
Machine-generated threat intelligence
Technical Analysis
The Linux kernel's accel/qaic driver had a vulnerability where the remap_pfn_range call in qaic_gem_object_mmap could remap memory beyond the bounds of the VMA if the buffer object was oversized. This could lead to use-after-free issues because munmap() would unmap only the VMA region, leaving additional mappings intact and potentially accessible. The vulnerability was addressed by adding an overflow check to ensure the remapped length does not exceed the VMA size, truncating it if sg->length is too large.
Potential Impact
The vulnerability could cause use-after-free conditions in kernel memory management related to mmap operations in the accel/qaic driver. This may lead to memory corruption or stability issues in affected systems. No known exploits in the wild have been reported.
Mitigation Recommendations
A fix has been implemented in the Linux kernel by adding an overflow check to remap_pfn_range during mmap in the accel/qaic driver. Users should apply the official kernel updates that include this fix. Patch status is not explicitly confirmed in the provided data; therefore, check the vendor or Linux kernel advisory for the current remediation guidance.
Technical Details
- Gcve Source
- db.gcve.eu
- Osv Id
- GHSA-26m7-cqmr-vwvj
- Osv Schema Version
- 1.4.0
- Aliases
- ["CVE-2026-64051"]
- Ecosystems
- []
- Database Specific Severity
- null
- Cvss Version
- null
Threat ID: 6a5d27a92a4a8d598912d202
Added to database: 07/19/2026, 19:38:17 UTC
Last enriched: 07/19/2026, 19:57:08 UTC
Last updated: 07/20/2026, 19:41:22 UTC
Views: 20
Community Reviews
0 reviewsCrowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.
Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.
Actions
Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.
Need more coverage?
Upgrade to Pro Console for AI refresh and higher limits.
For incident response and remediation, OffSeq services can help resolve threats faster.
Latest Threats
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.