CVE-2026-64209 is a vulnerability in Linux Kernel
Published on July 24, 2026
phy: qcom: qmp-usbc: Fix out-of-bounds array access in dp swing config
In the Linux kernel, the following vulnerability has been resolved:
phy: qcom: qmp-usbc: Fix out-of-bounds array access in dp swing config
swing_tbl and pre_emphasis_tbl are 4x4 arrays (valid indices 0-3), but
the boundary check uses "> 4" instead of ">= 4", allowing index 4 to
cause an out-of-bounds access.
Products Associated with CVE-2026-64209
Want to know whenever a new CVE is published for Linux Kernel? stack.watch will email you.
Affected Versions
Linux:- Version 81791c45c8e0eaeba9a40927eecd082a8500f709 and below cb35af6e7f3d5628178b58c631e305b1def8edf7 is affected.
- Version 81791c45c8e0eaeba9a40927eecd082a8500f709 and below ea17fc4d7dc2ba6459b1a318962960520201baf1 is affected.
- Version 7.0 is affected.
- Before 7.0 is unaffected.
- Version 7.0.11, <= 7.0.* is unaffected.
- Version 7.1, <= * is unaffected.