Answer in brief
CVE-2026-64219 records a Unknown severity vulnerability in drm/amd/display: Validate payload length and link_index in dc_process_dmub_aux_transfer_async. The current sources do not mark it as known exploited. The current feed maps Linux/Linux (generic), Linux/Linux (generic). Check affected ranges and fixed versions before updating.
Analysis pending evidence review
HOL Guard separates source facts from reviewed analysis. See the methodology.
Answer in brief
CVE-2026-64219 records a Unknown severity vulnerability in drm/amd/display: Validate payload length and link_index in dc_process_dmub_aux_transfer_async. The current sources do not mark it as known exploited. The current feed maps Linux/Linux (generic), Linux/Linux (generic). Check affected ranges and fixed versions before updating.
Analysis pending evidence review
HOL Guard separates source facts from reviewed analysis. See the methodology.
A CVSS score is not reported in the current record. The current sources do not mark it as known exploited. Treat this as a source-backed prioritization signal, not a statement about your environment.
Analysis status
Analysis pending evidence review
Factual feed record only; HOL analysis is not approved for indexing. Read the methodology.
The current feed maps Linux/Linux (generic), Linux/Linux (generic). Check affected ranges and fixed versions before updating.
| Package | Affected range | Fixed version |
|---|---|---|
| Linux/Linuxgeneric | >=4f8e37dbaf584de6d38f58b3000b0bfd7eaf2ff6 <d6590e3f766e3111dd1beaf88b9384d117acfa6b || >=4f8e37dbaf584de6d38f58b3000b0bfd7eaf2ff6 <16a5fa57565afb6bf37e18129921c270c93d8e2b || >=4f8e37dbaf584de6d38f58b3000b0bfd7eaf2ff6 <90c398e822ca76e40548df0c061dd4f93ea92d71 || >=4f8e37dbaf584de6d38f58b3000b0bfd7eaf2ff6 <3265f3ed373fb8048be713aadcdf702579a0e53d || >=4f8e37dbaf584de6d38f58b3000b0bfd7eaf2ff6 <1ecde19bfce6535bffddad1139ff466b6d401b8e || >=4f8e37dbaf584de6d38f58b3000b0bfd7eaf2ff6 <1c8c6e912f2945b2a3e669afca6b52174b88e86e || >=4f8e37dbaf584de6d38f58b3000b0bfd7eaf2ff6 <6c92f6d9600efa3ef0d9e560a2b52776d9803c29 | d6590e3f766e3111dd1beaf88b9384d117acfa6b, 16a5fa57565afb6bf37e18129921c270c93d8e2b, 90c398e822ca76e40548df0c061dd4f93ea92d71, 3265f3ed373fb8048be713aadcdf702579a0e53d, 1ecde19bfce6535bffddad1139ff466b6d401b8e, 1c8c6e912f2945b2a3e669afca6b52174b88e86e, 6c92f6d9600efa3ef0d9e560a2b52776d9803c29 |
| Linux/Linuxgeneric | 5.13 | Not reported |
Published upstream
Jul 24, 2026
Evidence: source:cvelist:source_dates:source-dates:recordSource modified
Aug 5, 2026
Evidence: source:cvelist:source_dates:source-dates:recordFirst seen by HOL
Aug 5, 2026
In the Linux kernel, the following vulnerability has been resolved: drm/amd/display: Validate payload length and link_index in dc_process_dmub_aux_transfer_async [Why&How] dc_process_dmub_aux_transfer_async() copies payload->length bytes into a 16-byte stack buffer (dpaux.data[16]) guarded only by an ASSERT(), which is a no-op in release builds. If a caller ever passes length > 16 this results in a stack buffer overflow via memcpy. Additionally, link_index is used to dereference dc->links[] without bounds checking against dc->link_count, risking an out-of-bounds access. Replace the ASSERT with a hard runtime check that returns false when payload->length exceeds the destination buffer size, and add a bounds check for link_index before it is used. (cherry picked from commit ba4caa9fecdf7a38f98c878ad05a8a64148b6881)
Quoted source text, attributed separately from HOL analysis.
A CVSS score is not reported in the current record. The current sources do not mark it as known exploited. Treat this as a source-backed prioritization signal, not a statement about your environment.
Analysis status
Analysis pending evidence review
Factual feed record only; HOL analysis is not approved for indexing. Read the methodology.
The current feed maps Linux/Linux (generic), Linux/Linux (generic). Check affected ranges and fixed versions before updating.
| Package | Affected range | Fixed version |
|---|---|---|
| Linux/Linuxgeneric | >=4f8e37dbaf584de6d38f58b3000b0bfd7eaf2ff6 <d6590e3f766e3111dd1beaf88b9384d117acfa6b || >=4f8e37dbaf584de6d38f58b3000b0bfd7eaf2ff6 <16a5fa57565afb6bf37e18129921c270c93d8e2b || >=4f8e37dbaf584de6d38f58b3000b0bfd7eaf2ff6 <90c398e822ca76e40548df0c061dd4f93ea92d71 || >=4f8e37dbaf584de6d38f58b3000b0bfd7eaf2ff6 <3265f3ed373fb8048be713aadcdf702579a0e53d || >=4f8e37dbaf584de6d38f58b3000b0bfd7eaf2ff6 <1ecde19bfce6535bffddad1139ff466b6d401b8e || >=4f8e37dbaf584de6d38f58b3000b0bfd7eaf2ff6 <1c8c6e912f2945b2a3e669afca6b52174b88e86e || >=4f8e37dbaf584de6d38f58b3000b0bfd7eaf2ff6 <6c92f6d9600efa3ef0d9e560a2b52776d9803c29 | d6590e3f766e3111dd1beaf88b9384d117acfa6b, 16a5fa57565afb6bf37e18129921c270c93d8e2b, 90c398e822ca76e40548df0c061dd4f93ea92d71, 3265f3ed373fb8048be713aadcdf702579a0e53d, 1ecde19bfce6535bffddad1139ff466b6d401b8e, 1c8c6e912f2945b2a3e669afca6b52174b88e86e, 6c92f6d9600efa3ef0d9e560a2b52776d9803c29 |
| Linux/Linuxgeneric | 5.13 | Not reported |
Published upstream
Jul 24, 2026
Evidence: source:cvelist:source_dates:source-dates:recordSource modified
Aug 5, 2026
Evidence: source:cvelist:source_dates:source-dates:recordFirst seen by HOL
Aug 5, 2026
In the Linux kernel, the following vulnerability has been resolved: drm/amd/display: Validate payload length and link_index in dc_process_dmub_aux_transfer_async [Why&How] dc_process_dmub_aux_transfer_async() copies payload->length bytes into a 16-byte stack buffer (dpaux.data[16]) guarded only by an ASSERT(), which is a no-op in release builds. If a caller ever passes length > 16 this results in a stack buffer overflow via memcpy. Additionally, link_index is used to dereference dc->links[] without bounds checking against dc->link_count, risking an out-of-bounds access. Replace the ASSERT with a hard runtime check that returns false when payload->length exceeds the destination buffer size, and add a bounds check for link_index before it is used. (cherry picked from commit ba4caa9fecdf7a38f98c878ad05a8a64148b6881)
Quoted source text, attributed separately from HOL analysis.