Memory corruption in Linux kernel - CVE-2026-80736
Published: September 4, 2026
Vulnerability details
The vulnerability allows an attacker with physical access to cause incorrect DisplayPort bandwidth reservation accounting.
The vulnerability exists due to an out-of-bounds array access in tb_consumed_dp_bandwidth() when processing a bandwidth group with ID MAX_GROUPS. An attacker with physical access can trigger processing of the maximum valid group ID to cause incorrect DisplayPort bandwidth reservation accounting.
Group ID 0 is reserved, while valid group IDs range from 1 through MAX_GROUPS.