๐Ÿ” CVE Alert

CVE-2026-80887

UNKNOWN 0.0

drm/vmwgfx: use check_add_overflow for shader size+offset bound

CVSS Score
0.0
EPSS Score
0.0%
EPSS Percentile
0th

In the Linux kernel, the following vulnerability has been resolved: drm/vmwgfx: use check_add_overflow for shader size+offset bound vmw_shader_define() validates the user-supplied shader window against its backing buffer with (u64)buffer->tbo.base.size < (u64)size + (u64)offset drm_vmw_shader_create_arg::offset is __u64 in the uapi; when it is near U64_MAX the unsigned addition wraps and the resulting tiny value passes the check. The unbounded offset is then stored in res->guest_memory_offset and forwarded to host SVGA shader-create commands. Use check_add_overflow() to detect the wrap and compare the resulting endpoint against the buffer size.

Vendor linux
Product linux
Ecosystems
Industries
Technology
Published Sep 4, 2026
Stay Ahead of the Next One

Get instant alerts for linux linux

Be the first to know when new unknown vulnerabilities affecting linux linux are published โ€” delivered to Slack, Telegram or Discord.

Get Free Alerts โ†’ Free ยท No credit card ยท 60 sec setup

Affected Versions

Linux / Linux
668b206601c5f5063e03b76784a0d3024fa2b249 < 1bbe7751f5ebac383405ef29a66622d65bd505d3 668b206601c5f5063e03b76784a0d3024fa2b249 < d3f44438aa805270aaead3b6840ccaea0f4c11f9 668b206601c5f5063e03b76784a0d3024fa2b249 < cfd163169af3be56eaef113c680ea251f0d09189 668b206601c5f5063e03b76784a0d3024fa2b249 < 5c725901908eb1e52a16fc0e2373cb761df42d21 668b206601c5f5063e03b76784a0d3024fa2b249 < 54d56d5b42d2e4c72ba6e365e9774da90698aa22
Linux / Linux
6.4

References

NVD โ†— CVE.org โ†— EPSS Data โ†—
git.kernel.org: https://git.kernel.org/stable/c/1bbe7751f5ebac383405ef29a66622d65bd505d3 git.kernel.org: https://git.kernel.org/stable/c/d3f44438aa805270aaead3b6840ccaea0f4c11f9 git.kernel.org: https://git.kernel.org/stable/c/cfd163169af3be56eaef113c680ea251f0d09189 git.kernel.org: https://git.kernel.org/stable/c/5c725901908eb1e52a16fc0e2373cb761df42d21 git.kernel.org: https://git.kernel.org/stable/c/54d56d5b42d2e4c72ba6e365e9774da90698aa22