SB2026090581 - Improper access control in Linux kernel alpha kernel
Published: September 5, 2026
Breakdown by Severity
- Low
- Medium
- High
- Critical
Description
This security bulletin contains information about 1 vulnerability.
1) Improper access control (CVE-ID: CVE-2026-80867)
CWE-ID: CWE-284 - Improper Access Control
CVSSv4: 8.5 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]
The vulnerability allows a local user to conduct DMA attacks.
The vulnerability exists due to improper access control in the Alpha-specific pci_mmap_resource() function when mapping PCI BARs while kernel lockdown is enabled. A local user can map a PCI BAR to conduct DMA attacks.
Remediation
Install update from vendor's website.
References
- https://git.kernel.org/stable/c/257b55dc3d18d7ef01f62a8ff7317871f7597e28
- https://git.kernel.org/stable/c/4de5ff924c0a8ef8166c1a68af9087826e1e8d61
- https://git.kernel.org/stable/c/6e368485a1ac19fbde0a8b6a332d4545ae72a8ac
- https://git.kernel.org/stable/c/78a228f0aa0e9eba31955950c8a40a9945e2c8bb
- https://git.kernel.org/stable/c/85f966b1120874fe530edec50d28373ceb06ebcd
- https://git.kernel.org/stable/c/94defb18ac792fd16407d5a52ad0d3f5055c4b43
- https://git.kernel.org/stable/c/c3234efe21d4198945492cf7dba6859476f0f6ff
- https://git.kernel.org/stable/c/ed2cd1fee0ed16a1c2dff49175e65c641eb8ae2b