In the Linux kernel, the following vulnerability has been resolved:
drm/shmem_helper: Check VMA boundaries for PMD mappings
In the ->huge_fault handler do not install a PMD huge page mapping if the huge page exceeds the boundaries of the VMA.
All other ->hugefault handlers have similar checks and the resulting mapping will trigger a VMBUGONVMA() if it ever reaches copypmdrange().
{
"osv_generated_from": "https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/80xxx/CVE-2026-80582.json",
"cna_assigner": "Linux"
}