In the Linux kernel, the following vulnerability has been resolved: vfio/pci: Check BAR resources before exporting a DMABUF A DMABUF exports access… (CVE-2026-64042)
In the Linux kernel, the following vulnerability has been resolved: vfio/pci: Check BAR resources before exporting a DMABUF A DMABUF exports access to BAR resources and, although they are requested at startup time, we need to ensure they really were reserved before exporting. Otherwise, it's possible to access unreserved resources through the export. Add a check to the DMABUF-creation path.
AI Analysis
Technical Summary
The Linux kernel vulnerability CVE-2026-64042 concerns the vfio/pci driver where DMABUF exports access to BAR (Base Address Register) resources. Although BAR resources are requested at startup, the kernel did not verify that these resources were truly reserved before allowing access via DMABUF exports. This flaw could allow access to unreserved BAR resources, potentially leading to unauthorized memory access. The fix involved adding a validation step in the DMABUF creation process to confirm BAR resource reservation before export.
Potential Impact
The vulnerability could allow unauthorized access to unreserved BAR resources through DMABUF exports, potentially exposing kernel memory or device resources that should not be accessible. No known exploits in the wild have been reported. The impact is limited to systems using the affected vfio/pci functionality in the Linux kernel.
Mitigation Recommendations
A fix has been implemented in the Linux kernel to add a check ensuring BAR resources are reserved before exporting a DMABUF. Users should apply the official kernel updates that include this patch. Patch status is not explicitly stated in the provided data; therefore, check the Linux kernel vendor advisory or distribution security advisories for the exact fixed versions and apply updates accordingly.
In the Linux kernel, the following vulnerability has been resolved: vfio/pci: Check BAR resources before exporting a DMABUF A DMABUF exports access… (CVE-2026-64042)
Description
In the Linux kernel, the following vulnerability has been resolved: vfio/pci: Check BAR resources before exporting a DMABUF A DMABUF exports access to BAR resources and, although they are requested at startup time, we need to ensure they really were reserved before exporting. Otherwise, it's possible to access unreserved resources through the export. Add a check to the DMABUF-creation path.
CVSS v3.1
AI-Powered Analysis
Machine-generated threat intelligence
Technical Analysis
The Linux kernel vulnerability CVE-2026-64042 concerns the vfio/pci driver where DMABUF exports access to BAR (Base Address Register) resources. Although BAR resources are requested at startup, the kernel did not verify that these resources were truly reserved before allowing access via DMABUF exports. This flaw could allow access to unreserved BAR resources, potentially leading to unauthorized memory access. The fix involved adding a validation step in the DMABUF creation process to confirm BAR resource reservation before export.
Potential Impact
The vulnerability could allow unauthorized access to unreserved BAR resources through DMABUF exports, potentially exposing kernel memory or device resources that should not be accessible. No known exploits in the wild have been reported. The impact is limited to systems using the affected vfio/pci functionality in the Linux kernel.
Mitigation Recommendations
A fix has been implemented in the Linux kernel to add a check ensuring BAR resources are reserved before exporting a DMABUF. Users should apply the official kernel updates that include this patch. Patch status is not explicitly stated in the provided data; therefore, check the Linux kernel vendor advisory or distribution security advisories for the exact fixed versions and apply updates accordingly.
Technical Details
- Gcve Source
- db.gcve.eu
- Osv Id
- GHSA-h9jg-4972-qw48
- Osv Schema Version
- 1.4.0
- Aliases
- ["CVE-2026-64042"]
- Ecosystems
- []
- Database Specific Severity
- null
- Cvss Version
- null
Threat ID: 6a5d27a92a4a8d598912cba5
Added to database: 07/19/2026, 19:38:17 UTC
Last enriched: 07/19/2026, 19:55:02 UTC
Last updated: 07/20/2026, 19:41:22 UTC
Views: 13
Community Reviews
0 reviewsCrowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.
Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.
Actions
Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.
Need more coverage?
Upgrade to Pro Console for AI refresh and higher limits.
For incident response and remediation, OffSeq services can help resolve threats faster.
Latest Threats
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.