CVE-2026-80541

Source
https://cve.org/CVERecord?id=CVE-2026-80541
Import Source
https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-80541.json
JSON Data
https://api.osv.dev/v1/vulns/CVE-2026-80541
Downstream
Published
2026-08-26T14:37:14Z
Modified
2026-08-28T03:47:29Z
Severity
  • 7.8 (High) CVSS_V3 - CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H CVSS Calculator
Summary
drm/amdgpu: validate GEM_CREATE domain combinations
Details

In the Linux kernel, the following vulnerability has been resolved:

drm/amdgpu: validate GEM_CREATE domain combinations

AMDGPU_GEM_CREATE checked domain bits against AMDGPU_GEM_DOMAIN_MASK, but did not validate domain combinations. Userspace could combine CPU|GTT|VRAM with DOORBELL, GDS, GWS, or OA, making amdgpu_bo_placement_from_domain() exceed AMDGPU_BO_MAX_PLACEMENTS and hit BUG_ON().

Allow combinations only within CPU/GTT/VRAM, and require non-CPU/GTT/ VRAM domains to be specified one at a time. Return -EINVAL for invalid combinations in amdgpu_gem_create_ioctl().

v2: Rename helper from amdgpu_gem_domain_valid() to amdgpu_gem_are_domains_valid() (Christian)

(cherry picked from commit db39852d0c39843cb02048dfb47e4b8c703e9080)

Database specific
{
    "cna_assigner": "Linux",
    "osv_generated_from": "https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/80xxx/CVE-2026-80541.json"
}
References

Affected packages

Git / git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git

Affected ranges

Type
GIT
Repo
https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git
Events
Introduced
77a2faa55c1a497f4e7e89eabd11830f0e3cb3dd
Fixed
5c73485af7ad9c3ae592db3481f370bc07705391
Fixed
584e3d47736fe2e7184ef3fc16b00b41485f96c6
Fixed
66133fc05c3af002f45de8a71b833c026ccbfba6
Fixed
ce5da474c3ddf7cccec5dce6aa4296297dd7caff
Fixed
493355096e397f9217b41c8574ed2784c7351443
Fixed
220aa2589d7321fb68d2e8597862711b5f22ae0b
Fixed
80f0b53860d02577709d69a312a29ca674b9297c
Fixed
5e9d136ad74df4edec67e502ce267597064d8f86

Database specific

source
"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-80541.json"

Linux / Kernel

Package

Name
Kernel

Affected ranges

Type
ECOSYSTEM
Events
Introduced
4.20.0
Fixed
5.10.266
Type
ECOSYSTEM
Events
Introduced
5.11.0
Fixed
5.15.217
Type
ECOSYSTEM
Events
Introduced
5.16.0
Fixed
6.1.184
Type
ECOSYSTEM
Events
Introduced
6.2.0
Fixed
6.6.153
Type
ECOSYSTEM
Events
Introduced
6.7.0
Fixed
6.12.105
Type
ECOSYSTEM
Events
Introduced
6.13.0
Fixed
6.18.46
Type
ECOSYSTEM
Events
Introduced
6.19.0
Fixed
7.1.10

Database specific

source
"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-80541.json"