Description
An integer overflow when calculating physical offsets for sparse PMRs may result in 32-bit truncation of address computations for PMRs larger than 4 GB. This can lead to incorrect GPU MMU mappings and may allow a non-privileged user to trigger access to unintended physical memory, resulting in memory corruption or information disclosure.
CVSS 9.8EPSS 0.295%Risk 1.01
View source- Published
- 2026-07-24 23:16:50
- Affected versions
- unknown
- Type
- Kernel
- Last modified
- 2026-07-28 16:17:58
- Vector
- CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H