SEPTEMBER 19, 2026
Live Feed
Back to database
Case File

CVE-2026-80888

UNKNOWN · CVSS N/A EPSS 0.18%

Source: NVD + CISA KEV + EPSS · Published 2026-09-04 · Last synced 2026-09-19

CyberRota Analysis

AI-Generated

The vulnerability affects the Linux kernel's handling of DMA buffer references in the drm/vmwgfx module, specifically during the import of foreign file descriptors. An unprivileged renderD client can exploit this flaw to leak a DMA buffer reference with each call, leading to resource exhaustion by indefinitely pinning the foreign exporter's GEM resources. Organizations utilizing affected Linux systems, particularly those with unprivileged rendering clients, should prioritize addressing this vulnerability to prevent potential denial-of-service conditions.

CVE
CVE-2026-80888
Severity
UNKNOWN
CVSS
N/A
EPSS
0.18%
Linux

Original NVD Description

In the Linux kernel, the following vulnerability has been resolved: drm/vmwgfx: drop dma_buf reference on foreign-fd prime import ttm_prime_fd_to_handle() returns -ENOSYS when the imported fd's dma_buf->ops do not match the ttm_object_device's ops, but does so without releasing the reference acquired by dma_buf_get(). Any unprivileged renderD client passing a non-vmwgfx prime fd through the DRM_VMW_GB_SURFACE_REF{,_EXT} path leaks one dma_buf reference per call and indefinitely pins the foreign exporter's GEM resources. Funnel the error path through the existing dma_buf_put() so the reference is always dropped.