CVE-2026-80703

Source
https://cve.org/CVERecord?id=CVE-2026-80703
Import Source
https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-80703.json
JSON Data
https://api.osv.dev/v1/vulns/CVE-2026-80703
Downstream
Published
2026-08-28T06:53:05Z
Modified
2026-09-01T03:30:39Z
Summary
drm/amdkfd: Fix missing authorization check in KFD_IOC_DBG_TRAP_DISABLE
Details

In the Linux kernel, the following vulnerability has been resolved:

drm/amdkfd: Fix missing authorization check in KFD_IOC_DBG_TRAP_DISABLE

Prevent unauthorized termination of active GPU debug sessions. Previously, users with /dev/kfd access could terminate another process's debug session without proper ownership or ptrace authorization.

(cherry picked from commit 4db4c5ffd5585b72622ecf6ffedf2da258ee23f5)

Database specific
{
    "cna_assigner": "Linux",
    "osv_generated_from": "https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/80xxx/CVE-2026-80703.json"
}
References

Affected packages

Git / git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git

Affected ranges

Type
GIT
Repo
https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git
Events
Introduced
0ab2d7532b05a3e7c06fd3b0c8bd6b46c1dfb508
Fixed
ce813614f63b020a826071276a92f2cfae7cba79
Fixed
b8c05061997408bf81759f2dd31cd5f66771d15f
Fixed
9e52212aff8ed1fd9087728f61243ce3efd9d0ac
Fixed
4070909ac042f44654aac72f7986ea550c96f591
Fixed
99b2fe4f19e3be0a8d0a0b5ea98d855970889653

Database specific

source
"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-80703.json"

Linux / Kernel

Package

Name
Kernel

Affected ranges

Type
ECOSYSTEM
Events
Introduced
6.5.0
Fixed
6.6.151
Type
ECOSYSTEM
Events
Introduced
6.7.0
Fixed
6.12.103
Type
ECOSYSTEM
Events
Introduced
6.13.0
Fixed
6.18.44
Type
ECOSYSTEM
Events
Introduced
6.19.0
Fixed
7.1.8

Database specific

source
"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-80703.json"