CVE-2026-80541

Source
https://cve.org/CVERecord?id=CVE-2026-80541
Import Source
https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-80541.json
JSON Data
https://api.osv.dev/v1/vulns/CVE-2026-80541
Downstream
Published
2026-08-26T14:37:14.572Z
Modified
2026-08-28T03:47:29.032294018Z
Severity
  • 7.8 (High) CVSS_V3 - CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H CVSS Calculator
Summary
drm/amdgpu: validate GEM_CREATE domain combinations
Details

In the Linux kernel, the following vulnerability has been resolved:

drm/amdgpu: validate GEM_CREATE domain combinations

AMDGPUGEMCREATE checked domain bits against AMDGPUGEMDOMAINMASK, but did not validate domain combinations. Userspace could combine CPU|GTT|VRAM with DOORBELL, GDS, GWS, or OA, making amdgpuboplacementfromdomain() exceed AMDGPUBOMAXPLACEMENTS and hit BUG_ON().

Allow combinations only within CPU/GTT/VRAM, and require non-CPU/GTT/ VRAM domains to be specified one at a time. Return -EINVAL for invalid combinations in amdgpugemcreate_ioctl().

v2: Rename helper from amdgpugemdomainvalid() to amdgpugemaredomains_valid() (Christian)

(cherry picked from commit db39852d0c39843cb02048dfb47e4b8c703e9080)

Database specific
{
    "osv_generated_from": "https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/80xxx/CVE-2026-80541.json",
    "cna_assigner": "Linux"
}
References

Affected packages

Git / git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git

Affected ranges

Type
GIT
Repo
https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git
Events
Introduced
77a2faa55c1a497f4e7e89eabd11830f0e3cb3dd
Fixed
5c73485af7ad9c3ae592db3481f370bc07705391
Fixed
584e3d47736fe2e7184ef3fc16b00b41485f96c6
Fixed
66133fc05c3af002f45de8a71b833c026ccbfba6
Fixed
ce5da474c3ddf7cccec5dce6aa4296297dd7caff
Fixed
493355096e397f9217b41c8574ed2784c7351443
Fixed
220aa2589d7321fb68d2e8597862711b5f22ae0b
Fixed
80f0b53860d02577709d69a312a29ca674b9297c
Fixed
5e9d136ad74df4edec67e502ce267597064d8f86

Database specific

source
"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-80541.json"

Linux / Kernel

Package

Name
Kernel

Affected ranges

Type
ECOSYSTEM
Events
Introduced
4.20.0
Fixed
5.10.266
Type
ECOSYSTEM
Events
Introduced
5.11.0
Fixed
5.15.217
Type
ECOSYSTEM
Events
Introduced
5.16.0
Fixed
6.1.184
Type
ECOSYSTEM
Events
Introduced
6.2.0
Fixed
6.6.153
Type
ECOSYSTEM
Events
Introduced
6.7.0
Fixed
6.12.105
Type
ECOSYSTEM
Events
Introduced
6.13.0
Fixed
6.18.46
Type
ECOSYSTEM
Events
Introduced
6.19.0
Fixed
7.1.10

Database specific

source
"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-80541.json"