CVE-2026-80700
CVE CVE-2026-80700EUVD EUVD-2026-67435Veröffentlicht 2026-08-28T06:53:04.000ZZuletzt geändert 2026-08-29T06:22:20.000ZCVSS 7.8
Was das Advisory beschreibt
In the Linux kernel, the following vulnerability has been resolved: drm/vmwgfx: validate external BO copy bounds for both stride paths vmw_external_bo_copy() trusts caller-supplied offsets, strides, and heights and operates on imported dma-buf vmaps: - The equal-stride memcpy() bound was clamped after subtracting the offsets from dst_size and src_size; an offset larger than the BO size wraps the unsigned subtraction to a huge value and the resulting memcpy() runs off the end of the vmap. dst_stride * height is also a u32 multiplication that can overflow. - The non-equal-stride row-by-row path had no bound at all. The loop touches bytes through offset + (height - 1) * stride + width_in_bytes, with only a WARN_ON(dst_stride < width_in_bytes), and could likewise step past the end of either mapping. The offsets and strides are derived from STDU/SOU plane state, so a configured CRTC submitting a crafted atomic commit on an imported framebuffer can reach this path. Validate the exact row-copy endpoint against each BO's size up front using check_mul_overflow() and check_add_overflow(). Use the bulk memcpy() path only when width_in_bytes covers the whole stride; otherwise copy one row at a time so partial-row updates near the bottom of a framebuffer remain valid. Also reject zero strides and stride < width_in_bytes, both of which the row-by-row path cannot represent safely.
Quelle: EUVD (ENISA), im Wortlaut der Meldung.
Produkte, die das Advisory nennt
Diese Angaben stammen aus der Meldung selbst, nicht aus einer Prüfung durch uns.
- Linux — Linux 9a9716bbbf3dd6b6cbefba3abcc89af8b72631f4 <4e0f669e2951b742239c6fe847fcc406fe78748d; patch: 0; patch: 7.1.8; patch: 6.18.44; 50f1199250912568606b3778dc56646c10cb7b04 <5e4a2d15637a906cbd9bc98e0bf969f5f713e344; patch: 7.2; 6.10.8 <6.11; 50f1199250912568606b3778dc56646c10cb7b04 <706c93c5813caabbb0d0a576c017d15aeec2c113; 6.11; 50f1199250912568606b3778dc56646c10cb7b04 <042ca38779554687fc32b66a28328e0d9a36c58f; 5c12391ee1ab59cb2f3be3f1f5e6d0fc0c2dc854; patch: 6.12.103; patch: 6.6.151; 6.6.49 <6.6.151; 50f1199250912568606b3778dc56646c10cb7b04 <e7b25a6011781ebfdbc458552cae6d4156732771
Die genannten Versionen sind die Angabe der Meldung. Patchlage vergleicht keine Versionsnummern und leitet aus ihnen keine Aussage ab — welche Version installiert ist, muss ein Mensch nachsehen.
Im Produktkatalog geführt
Für diese Produkte kann ein Bestand in Patchlage erfasst werden. Ein Advisory dazu erscheint am Morgen danach im Lagebericht.
- Linux — Linux
Betrifft das einen Ihrer Kundenbestände?
Diese Seite kann die Frage nicht beantworten — sie kennt Ihren Bestand nicht. Wer seine Umgebungen erfasst hat, bekommt die Antwort am Morgen nach der Veröffentlichung, zusammen mit einem Absatz, den er unverändert an den Kunden weitergeben kann.
28 Tage testenPatchlage meldet Treffer und Verdachtsfälle. Zu allem anderen sagt dieses System nichts — weder diese Seite noch der Lagebericht behauptet je, dass ein Bestand sicher ist.