Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

Количество 6

Количество 6

ubuntu логотип

CVE-2026-64280

7 дней назад

In the Linux kernel, the following vulnerability has been resolved: fpga: dfl-afu: validate DMA mapping length in afu_dma_map_region() afu_ioctl_dma_map() accepts a 64-bit length from userspace via DFL_FPGA_PORT_DMA_MAP ioctl without an upper bound check. The value is passed to afu_dma_pin_pages() where npages is derived as length >> PAGE_SHIFT and passed to pin_user_pages_fast() which takes int nr_pages, causing implicit truncation if length is very large. Validate map.length at the ioctl entry point before calling afu_dma_map_region(), rejecting values whose page count exceeds INT_MAX.

CVSS3: 8.8
EPSS: Низкий
redhat логотип

CVE-2026-64280

8 дней назад

A flaw was found in the Linux kernel's `dfl-afu` FPGA driver. A local user could exploit this vulnerability by providing an excessively large length value during Direct Memory Access (DMA) mapping operations. The system incorrectly truncates this value, leading to memory corruption. This could allow a local attacker to gain elevated privileges or execute arbitrary code on the system.

CVSS3: 7
EPSS: Низкий
nvd логотип

CVE-2026-64280

7 дней назад

In the Linux kernel, the following vulnerability has been resolved: fpga: dfl-afu: validate DMA mapping length in afu_dma_map_region() afu_ioctl_dma_map() accepts a 64-bit length from userspace via DFL_FPGA_PORT_DMA_MAP ioctl without an upper bound check. The value is passed to afu_dma_pin_pages() where npages is derived as length >> PAGE_SHIFT and passed to pin_user_pages_fast() which takes int nr_pages, causing implicit truncation if length is very large. Validate map.length at the ioctl entry point before calling afu_dma_map_region(), rejecting values whose page count exceeds INT_MAX.

CVSS3: 8.8
EPSS: Низкий
msrc логотип

CVE-2026-64280

7 дней назад

fpga: dfl-afu: validate DMA mapping length in afu_dma_map_region()

EPSS: Низкий
debian логотип

CVE-2026-64280

7 дней назад

In the Linux kernel, the following vulnerability has been resolved: f ...

CVSS3: 8.8
EPSS: Низкий
github логотип

GHSA-hj85-3f53-vrg4

7 дней назад

In the Linux kernel, the following vulnerability has been resolved: fpga: dfl-afu: validate DMA mapping length in afu_dma_map_region() afu_ioctl_dma_map() accepts a 64-bit length from userspace via DFL_FPGA_PORT_DMA_MAP ioctl without an upper bound check. The value is passed to afu_dma_pin_pages() where npages is derived as length >> PAGE_SHIFT and passed to pin_user_pages_fast() which takes int nr_pages, causing implicit truncation if length is very large. Validate map.length at the ioctl entry point before calling afu_dma_map_region(), rejecting values whose page count exceeds INT_MAX.

CVSS3: 8.8
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
ubuntu логотип
CVE-2026-64280

In the Linux kernel, the following vulnerability has been resolved: fpga: dfl-afu: validate DMA mapping length in afu_dma_map_region() afu_ioctl_dma_map() accepts a 64-bit length from userspace via DFL_FPGA_PORT_DMA_MAP ioctl without an upper bound check. The value is passed to afu_dma_pin_pages() where npages is derived as length >> PAGE_SHIFT and passed to pin_user_pages_fast() which takes int nr_pages, causing implicit truncation if length is very large. Validate map.length at the ioctl entry point before calling afu_dma_map_region(), rejecting values whose page count exceeds INT_MAX.

CVSS3: 8.8
0%
Низкий
7 дней назад
redhat логотип
CVE-2026-64280

A flaw was found in the Linux kernel's `dfl-afu` FPGA driver. A local user could exploit this vulnerability by providing an excessively large length value during Direct Memory Access (DMA) mapping operations. The system incorrectly truncates this value, leading to memory corruption. This could allow a local attacker to gain elevated privileges or execute arbitrary code on the system.

CVSS3: 7
0%
Низкий
8 дней назад
nvd логотип
CVE-2026-64280

In the Linux kernel, the following vulnerability has been resolved: fpga: dfl-afu: validate DMA mapping length in afu_dma_map_region() afu_ioctl_dma_map() accepts a 64-bit length from userspace via DFL_FPGA_PORT_DMA_MAP ioctl without an upper bound check. The value is passed to afu_dma_pin_pages() where npages is derived as length >> PAGE_SHIFT and passed to pin_user_pages_fast() which takes int nr_pages, causing implicit truncation if length is very large. Validate map.length at the ioctl entry point before calling afu_dma_map_region(), rejecting values whose page count exceeds INT_MAX.

CVSS3: 8.8
0%
Низкий
7 дней назад
msrc логотип
CVE-2026-64280

fpga: dfl-afu: validate DMA mapping length in afu_dma_map_region()

0%
Низкий
7 дней назад
debian логотип
CVE-2026-64280

In the Linux kernel, the following vulnerability has been resolved: f ...

CVSS3: 8.8
0%
Низкий
7 дней назад
github логотип
GHSA-hj85-3f53-vrg4

In the Linux kernel, the following vulnerability has been resolved: fpga: dfl-afu: validate DMA mapping length in afu_dma_map_region() afu_ioctl_dma_map() accepts a 64-bit length from userspace via DFL_FPGA_PORT_DMA_MAP ioctl without an upper bound check. The value is passed to afu_dma_pin_pages() where npages is derived as length >> PAGE_SHIFT and passed to pin_user_pages_fast() which takes int nr_pages, causing implicit truncation if length is very large. Validate map.length at the ioctl entry point before calling afu_dma_map_region(), rejecting values whose page count exceeds INT_MAX.

CVSS3: 8.8
0%
Низкий
7 дней назад

Уязвимостей на страницу