CVE-2026-64209: Linux Kernel

High severity, CVSS 7.1. EPSS: 0.2% chance of exploitation in the next 30 days.

In the Linux kernel, the following vulnerability has been resolved: phy: qcom: qmp-usbc: Fix out-of-bounds array access in dp swing config swing_tbl and pre_emphasis_tbl are 4x4 arrays (valid indices 0-3), but the boundary check uses "> 4" instead of ">= 4", allowing index 4 to cause an out-of-bounds access.

Affected products

  • Linux Linux Kernel: from 7.0, before 7.0.11 (fixed in 7.0.11); version 7.1 only

Published 2026-07-24. Last modified 2026-08-12.