Out-of-bounds write in Linux kernel - CVE-2026-80700
Published: August 28, 2026
Vulnerability details
The vulnerability allows a local user to cause a denial of service.
The vulnerability exists due to out-of-bounds write in vmw_external_bo_copy() when processing a crafted atomic commit on an imported framebuffer. A local user can submit crafted STDU/SOU plane state values to trigger out-of-bounds access and cause a denial of service.
Exploitation requires a configured CRTC and reaches the vulnerable path through imported dma-buf mappings.
Affected software
How to mitigate CVE-2026-80700
External References
- https://git.kernel.org/stable/c/042ca38779554687fc32b66a28328e0d9a36c58f
- https://git.kernel.org/stable/c/4e0f669e2951b742239c6fe847fcc406fe78748d
- https://git.kernel.org/stable/c/5e4a2d15637a906cbd9bc98e0bf969f5f713e344
- https://git.kernel.org/stable/c/706c93c5813caabbb0d0a576c017d15aeec2c113
- https://git.kernel.org/stable/c/e7b25a6011781ebfdbc458552cae6d4156732771