CVE-2026-80888
CVE CVE-2026-80888EUVD EUVD-2026-71638Published 2026-09-04T17:11:04.000Z
What the advisory describes
In the Linux kernel, the following vulnerability has been resolved: drm/vmwgfx: drop dma_buf reference on foreign-fd prime import ttm_prime_fd_to_handle() returns -ENOSYS when the imported fd's dma_buf->ops do not match the ttm_object_device's ops, but does so without releasing the reference acquired by dma_buf_get(). Any unprivileged renderD client passing a non-vmwgfx prime fd through the DRM_VMW_GB_SURFACE_REF{,_EXT} path leaks one dma_buf reference per call and indefinitely pins the foreign exporter's GEM resources. Funnel the error path through the existing dma_buf_put() so the reference is always dropped.
Source: EUVD (ENISA), in the words of the advisory.
Products the advisory names
These come from the advisory itself, not from any check we performed.
- Linux — Linux 65981f7681abdf92b25942222b629b9c512d0705 <c1c22fca0a0896a452a7cb92422d67babd65b4be; 65981f7681abdf92b25942222b629b9c512d0705 <f739416dc555fa205a785e5135d73fa39b26f35d; patch: 7.2; patch: 6.18.44; patch: 6.12.103; patch: 0; 65981f7681abdf92b25942222b629b9c512d0705 <4df39eb99bb47d1f24d1952c23b21b10988356bf; patch: 6.1.183; 65981f7681abdf92b25942222b629b9c512d0705 <a8434b145b1e467940334c58c00af241e9494c5f; 3.13; 65981f7681abdf92b25942222b629b9c512d0705 <a1e972fa94c3a8069e022c67b9d97c7aa7b05293; patch: 7.1.8; patch: 6.6.151; 65981f7681abdf92b25942222b629b9c512d0705 <619c3cfa88e09603a13d918f754808db2dda7057
The versions shown are the advisory's own. Patchlage compares no version numbers and derives no judgement from them — which version is installed is something a person has to look up.
Carried in the product catalogue
An estate covering these products can be recorded in Patchlage. An advisory about them appears in the next morning's situation report.
- Linux — Linux
Does this concern one of your customers?
This page cannot answer that — it does not know your estate. Whoever has recorded their environments gets the answer the morning after publication, together with a paragraph they can forward to the customer unedited.
Try it for 28 daysPatchlage reports hits and suspected hits. About everything else this system says nothing — neither this page nor the situation report ever claims that an estate is safe.