{"id":"CVE-2026-64280","summary":"fpga: dfl-afu: validate DMA mapping length in afu_dma_map_region()","details":"In the Linux kernel, the following vulnerability has been resolved:\n\nfpga: dfl-afu: validate DMA mapping length in afu_dma_map_region()\n\nafu_ioctl_dma_map() accepts a 64-bit length from userspace via\nDFL_FPGA_PORT_DMA_MAP ioctl without an upper bound check. The value\nis passed to afu_dma_pin_pages() where npages is derived as\nlength \u003e\u003e PAGE_SHIFT and passed to pin_user_pages_fast() which takes\nint nr_pages, causing implicit truncation if length is very large.\n\nValidate map.length at the ioctl entry point before calling\nafu_dma_map_region(), rejecting values whose page count exceeds\nINT_MAX.","modified":"2026-08-25T03:30:42.353244325Z","published":"2026-07-25T08:49:23.753Z","related":["openSUSE-SU-2026:11476-1"],"database_specific":{"cna_assigner":"Linux","osv_generated_from":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/64xxx/CVE-2026-64280.json"},"references":[{"type":"WEB","url":"https://git.kernel.org/stable/c/16381bda90b261a656ded0568630c1b857b2ebc8"},{"type":"WEB","url":"https://git.kernel.org/stable/c/5352d488ce4ae5e8c68c080ad4c3a5f084ad5fbc"},{"type":"WEB","url":"https://git.kernel.org/stable/c/59070040fd12e0b78d7b4d341d9f9a183237c5ff"},{"type":"WEB","url":"https://git.kernel.org/stable/c/a6a3884ff500f04f3088d6d09eec803cd35331a2"},{"type":"WEB","url":"https://git.kernel.org/stable/c/b50e6cd2395cde615f59b624819998d28c0668d6"},{"type":"WEB","url":"https://git.kernel.org/stable/c/d7e787eee2ea619b6dbb98890472ee73daf2e7fd"},{"type":"WEB","url":"https://git.kernel.org/stable/c/fb2c0eab51ae5b02d2bae7d67c2cfbec39b57231"},{"type":"WEB","url":"https://git.kernel.org/stable/c/fc3b071a7c8dc0f5d56defddf6e6fd5aaa3e1e27"},{"type":"ADVISORY","url":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/64xxx/CVE-2026-64280.json"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-64280"},{"type":"PACKAGE","url":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git"}],"affected":[{"ranges":[{"type":"GIT","repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","events":[{"introduced":"fa8dda1edef9ebc3af467c644c5533ac97171e12"},{"fixed":"5352d488ce4ae5e8c68c080ad4c3a5f084ad5fbc"},{"fixed":"d7e787eee2ea619b6dbb98890472ee73daf2e7fd"},{"fixed":"a6a3884ff500f04f3088d6d09eec803cd35331a2"},{"fixed":"16381bda90b261a656ded0568630c1b857b2ebc8"},{"fixed":"b50e6cd2395cde615f59b624819998d28c0668d6"},{"fixed":"59070040fd12e0b78d7b4d341d9f9a183237c5ff"},{"fixed":"fb2c0eab51ae5b02d2bae7d67c2cfbec39b57231"},{"fixed":"fc3b071a7c8dc0f5d56defddf6e6fd5aaa3e1e27"}]}],"database_specific":{"source":"https://storage.googleapis.com/osv-test-cve-osv-conversion/osv-output/CVE-2026-64280.json"}},{"package":{"name":"Kernel","ecosystem":"Linux"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"4.19.0"},{"fixed":"5.10.266"}]},{"type":"ECOSYSTEM","events":[{"introduced":"5.11.0"},{"fixed":"5.15.217"}]},{"type":"ECOSYSTEM","events":[{"introduced":"5.16.0"},{"fixed":"6.1.184"}]},{"type":"ECOSYSTEM","events":[{"introduced":"6.2.0"},{"fixed":"6.6.148"}]},{"type":"ECOSYSTEM","events":[{"introduced":"6.7.0"},{"fixed":"6.12.101"}]},{"type":"ECOSYSTEM","events":[{"introduced":"6.13.0"},{"fixed":"6.18.39"}]},{"type":"ECOSYSTEM","events":[{"introduced":"6.19.0"},{"fixed":"7.1.4"}]}],"database_specific":{"source":"https://storage.googleapis.com/osv-test-cve-osv-conversion/osv-output/CVE-2026-64280.json"}}],"schema_version":"1.9.0","severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H"}]}