CVE-2026-64049
Last modified
CVE-2026-64049 is a vulnerability of currently unknown severity. In the Linux kernel, the following vulnerability has been resolved: drm/msm/adreno: fix userspace-triggered crash on a2xx-a4xx Before a5xx Adreno driver will not try fetching UBWC params (because those generations didn't support UBWC anyway), however it's still possible to query UBWC-related params from the userspace, triggering possible NULL pointer dereference. Check for UBWC config in adreno_get_param() and return sane defaults if there is none. Patchwork: https://patchwork.freedesktop.org/patch/717778/. EPSS estimates a 0.17% chance of exploitation in the next 30 days.
Description
In the Linux kernel, the following vulnerability has been resolved: drm/msm/adreno: fix userspace-triggered crash on a2xx-a4xx Before a5xx Adreno driver will not try fetching UBWC params (because those generations didn't support UBWC anyway), however it's still possible to query UBWC-related params from the userspace, triggering possible NULL pointer dereference. Check for UBWC config in adreno_get_param() and return sane defaults if there is none. Patchwork: https://patchwork.freedesktop.org/patch/717778/
Metrics
Affected Software
Source: CNA advisory (CVE.org). NVD analysis pending.
| Vendor | Product | Versions |
|---|---|---|
| Linux | Linux | >= a452510aad53f665eb422784ff525c4889aa246f, < eea43d5ed45089705bc5d70971c39076962d5951; >= a452510aad53f665eb422784ff525c4889aa246f, < 22fc33d9b67694b24e0deb3f08c622464338cecb; >= a452510aad53f665eb422784ff525c4889aa246f, < 2b4abf879360ea00a9e2b46d2d15dcdbc0687eed |
| Linux | Linux | 6.17 |
References
Timeline
- Published
- Last Modified
- Status
- Awaiting Analysis
Frequently Asked Questions
What is CVE-2026-64049?
How severe is CVE-2026-64049?
How do I fix CVE-2026-64049?
How Strix Helps
- How Strix found a critical auth bypass in etcdStrix autonomously discovered a critical authentication bypass in etcd, later designated CVE-2026-33413.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2026
- CVE-2026-64043In the Linux kernel, the following vulnerability has been re…
- CVE-2026-64044In the Linux kernel, the following vulnerability has been re…7.8
- CVE-2026-64045In the Linux kernel, the following vulnerability has been re…8.4
- CVE-2026-64046In the Linux kernel, the following vulnerability has been re…9.8
- CVE-2026-64047In the Linux kernel, the following vulnerability has been re…9.8
- CVE-2026-64048In the Linux kernel, the following vulnerability has been re…7.5
- CVE-2026-6405The Anomify AI – Anomaly Detection and Alerting plugin for W…4.3
- CVE-2026-64050In the Linux kernel, the following vulnerability has been re…7.8
- CVE-2026-64051In the Linux kernel, the following vulnerability has been re…7.8
- CVE-2026-64052In the Linux kernel, the following vulnerability has been re…
- CVE-2026-64053In the Linux kernel, the following vulnerability has been re…7.8
- CVE-2026-64054In the Linux kernel, the following vulnerability has been re…
Are you affected by CVE-2026-64049?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
