{"id":"CVE-2026-64039","summary":"drm/msm/snapshot: fix dumping of the unaligned regions","details":"In the Linux kernel, the following vulnerability has been resolved:\n\ndrm/msm/snapshot: fix dumping of the unaligned regions\n\nThe snapshotting code internally aligns data segment to 16 bytes. This\nworks fine for DPU code (where most of the regions are aligned), but\nfails for snapshotting of the DSI data (because DSI data region is\nshifted by 4 bytes). Fix the code by removing length alignment and by\naccurately printing last registers in the region. While reworking the\ncode also fix the 16x memory overallocation in\nmsm_disp_state_dump_regs().\n\nPatchwork: https://patchwork.freedesktop.org/patch/725449/","modified":"2026-07-21T03:47:48.417012182Z","published":"2026-07-19T15:39:26.695Z","database_specific":{"cna_assigner":"Linux","osv_generated_from":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/64xxx/CVE-2026-64039.json"},"references":[{"type":"WEB","url":"https://git.kernel.org/stable/c/070e40acc59ef7bedba0314f59971ba87fcc8ab0"},{"type":"WEB","url":"https://git.kernel.org/stable/c/0c90ececfad3fc5c4c43a75ece0e2d736ab3def1"},{"type":"WEB","url":"https://git.kernel.org/stable/c/1ef79be774706dddcfcace0331fa7ff32a73c73e"},{"type":"WEB","url":"https://git.kernel.org/stable/c/76824d2467feb1828b745d6add2541918d7be3da"},{"type":"WEB","url":"https://git.kernel.org/stable/c/8fb070cf95847b29ef6cb15ec2c0de2bf4704676"},{"type":"WEB","url":"https://git.kernel.org/stable/c/cdd1aaf0ee962f50810b9aef7928f2313989d55f"},{"type":"WEB","url":"https://git.kernel.org/stable/c/cecd34e046121d788a70b5c8b4f8a88916637953"},{"type":"ADVISORY","url":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/64xxx/CVE-2026-64039.json"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-64039"},{"type":"PACKAGE","url":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git"}],"affected":[{"ranges":[{"type":"GIT","repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","events":[{"introduced":"98659487b845c05b6bed85d881713545db674c7c"},{"fixed":"8fb070cf95847b29ef6cb15ec2c0de2bf4704676"},{"fixed":"cecd34e046121d788a70b5c8b4f8a88916637953"},{"fixed":"070e40acc59ef7bedba0314f59971ba87fcc8ab0"},{"fixed":"1ef79be774706dddcfcace0331fa7ff32a73c73e"},{"fixed":"cdd1aaf0ee962f50810b9aef7928f2313989d55f"},{"fixed":"0c90ececfad3fc5c4c43a75ece0e2d736ab3def1"},{"fixed":"76824d2467feb1828b745d6add2541918d7be3da"}]}],"database_specific":{"source":"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-64039.json"}},{"package":{"name":"Kernel","ecosystem":"Linux"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"5.14.0"},{"fixed":"5.15.209"}]},{"type":"ECOSYSTEM","events":[{"introduced":"5.16.0"},{"fixed":"6.1.175"}]},{"type":"ECOSYSTEM","events":[{"introduced":"6.2.0"},{"fixed":"6.6.142"}]},{"type":"ECOSYSTEM","events":[{"introduced":"6.7.0"},{"fixed":"6.12.92"}]},{"type":"ECOSYSTEM","events":[{"introduced":"6.13.0"},{"fixed":"6.18.34"}]},{"type":"ECOSYSTEM","events":[{"introduced":"6.19.0"},{"fixed":"7.0.11"}]}],"database_specific":{"source":"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-64039.json"}}],"schema_version":"1.7.5","severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:H"}]}