What is CVE-2026-64280?
The CVE-2026-64280 vulnerability in the Linux kernel affects the DFL-AFU FPGA driver, where the `afu_ioctl_dma_map()` function fails to validate the user-supplied DMA mapping length via the `DFL_FPGA_PORT_DMA_MAP` ioctl. This could lead to potential memory safety issues, and applying the security patch is recommended for affected systems.
Azərbaycanca: Linux kernel-də aşkar edilən CVE-2026-64280 zəifliyi `fpga: dfl-afu` sürücüsündə `afu_ioctl_dma_map()` funksiyasında istifadəçidən gələn DMA xəritələmə uzunluğunun yoxlanılmaması ilə bağlıdır. Bu, `DFL_FPGA_PORT_DMA_MAP` ioctl çağırışı vasitəsilə potensial olaraq yaddaş problemlərinə səbəb ola bilər. Təsirə məruz qalan sistemlərdə təhlükəsizlik yamasını tətbiq etmək tövsiyə olunur.
FAQ2
Which component of the Linux kernel is affected by CVE-2026-64280?
This vulnerability affects the `fpga: dfl-afu` driver in the Linux kernel.
What user-supplied parameter is not properly validated in CVE-2026-64280?
This vulnerability is caused by the failure to validate the user-supplied DMA mapping length via the `DFL_FPGA_PORT_DMA_MAP` ioctl call.
See also6
This explainer is AI-written from source data — skopnix's own reporting on this CVE; CVSS scores, vendors and versions are never invented. See NVD for the official record.