---
id: CVE-2026-64219
title: >-
  In the Linux kernel, the following vulnerability has been resolved:


  drm/amd/display: Validate payload length and link_index in
  dc_process_dmub_aux_transfer_async


  [Why&How]

  dc_process_dmub_aux_transfer_async() copies payload->length byt…
summary: >-
  In the Linux kernel, the following vulnerability has been resolved:


  drm/amd/display: Validate payload length and link_index in
  dc_process_dmub_aux_transfer_async


  [Why&How]

  dc_process_dmub_aux_transfer_async() copies payload->length byt…
severity: high
cvss: 7
cvssVector: 'CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H'
published: '2026-07-24'
updated: '2026-07-27'
source: NVD
sourceUrl: 'https://nvd.nist.gov/vuln/detail/CVE-2026-64219'
references:
  - url: 'https://git.kernel.org/stable/c/16a5fa57565afb6bf37e18129921c270c93d8e2b'
    label: 416baaa9-dc9f-4396-8d5f-8c081fb06d67
  - url: 'https://git.kernel.org/stable/c/1c8c6e912f2945b2a3e669afca6b52174b88e86e'
    label: 416baaa9-dc9f-4396-8d5f-8c081fb06d67
  - url: 'https://git.kernel.org/stable/c/1ecde19bfce6535bffddad1139ff466b6d401b8e'
    label: 416baaa9-dc9f-4396-8d5f-8c081fb06d67
  - url: 'https://git.kernel.org/stable/c/3265f3ed373fb8048be713aadcdf702579a0e53d'
    label: 416baaa9-dc9f-4396-8d5f-8c081fb06d67
  - url: 'https://git.kernel.org/stable/c/6c92f6d9600efa3ef0d9e560a2b52776d9803c29'
    label: 416baaa9-dc9f-4396-8d5f-8c081fb06d67
  - url: 'https://git.kernel.org/stable/c/90c398e822ca76e40548df0c061dd4f93ea92d71'
    label: 416baaa9-dc9f-4396-8d5f-8c081fb06d67
  - url: 'https://git.kernel.org/stable/c/d6590e3f766e3111dd1beaf88b9384d117acfa6b'
    label: 416baaa9-dc9f-4396-8d5f-8c081fb06d67
tags:
  - nvd
epss: 0.00168
epssPercentile: 0.05414
ingestedAt: '2026-07-27T06:16:49.135Z'
---

## Overview

In the Linux kernel, the following vulnerability has been resolved:

drm/amd/display: Validate payload length and link_index in dc_process_dmub_aux_transfer_async

[Why&How]
dc_process_dmub_aux_transfer_async() copies payload->length bytes into a
16-byte stack buffer (dpaux.data[16]) guarded only by an ASSERT(), which
is a no-op in release builds. If a caller ever passes length > 16 this
results in a stack buffer overflow via memcpy.

Additionally, link_index is used to dereference dc->links[] without
bounds checking against dc->link_count, risking an out-of-bounds access.

Replace the ASSERT with a hard runtime check that returns false when
payload->length exceeds the destination buffer size, and add a bounds
check for link_index before it is used.

(cherry picked from commit ba4caa9fecdf7a38f98c878ad05a8a64148b6881)

## Remediation

Refer to the linked advisories for vendor-supplied fixes and affected version ranges.
