Bug 2506783 (CVE-2026-64209)

Summary: CVE-2026-64209 kernel: phy: qcom: qmp-usbc: Fix out-of-bounds array access in dp swing config
Product: [Other] Security Response Reporter: OSIDB Bzimport <bzimport>
Component: vulnerabilityAssignee: Product Security <prodsec-ir-bot>
Status: NEW --- QA Contact:
Severity: unspecified Docs Contact:
Priority: unspecified    
Version: unspecifiedCC: rhel-process-autobot, watson-tool-maintainers
Target Milestone: ---Keywords: Security
Target Release: ---   
Hardware: All   
OS: Linux   
Whiteboard:
Fixed In Version: Doc Type: ---
Doc Text:
A flaw was found in the Linux kernel, specifically within the Qualcomm (QCOM) QMP USBC PHY (Physical Layer) driver. An incorrect boundary check during the configuration of DisplayPort (DP) swing settings allows for an out-of-bounds array access. This vulnerability can lead to memory corruption, potentially impacting system stability or allowing for further exploitation.
Story Points: ---
Clone Of: Environment:
Last Closed: Type: ---
Regression: --- Mount Type: ---
Documentation: --- CRM:
Verified Versions: Category: ---
oVirt Team: --- RHEL 7.3 requirements from Atomic Host:
Cloudforms Team: --- Target Upstream Version:
Embargoed:

Description OSIDB Bzimport 2026-07-24 16:02:25 UTC
In the Linux kernel, the following vulnerability has been resolved:

phy: qcom: qmp-usbc: Fix out-of-bounds array access in dp swing config

swing_tbl and pre_emphasis_tbl are 4x4 arrays (valid indices 0-3), but
the boundary check uses "> 4" instead of ">= 4", allowing index 4 to
cause an out-of-bounds access.

Comment 1 Mauro Matteo Cascella 2026-07-28 09:12:43 UTC
Upstream advisory:
https://lore.kernel.org/linux-cve-announce/2026072413-CVE-2026-64209-c7bb@gregkh/T