CVE-2026-80867

Source
https://cve.org/CVERecord?id=CVE-2026-80867
Import Source
https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-80867.json
JSON Data
https://api.osv.dev/v1/vulns/CVE-2026-80867
Downstream
Published
2026-09-04T16:48:15.723Z
Modified
2026-09-06T03:46:54.664084593Z
Summary
alpha/PCI: Add security_locked_down() check to pci_mmap_resource()
Details

In the Linux kernel, the following vulnerability has been resolved:

alpha/PCI: Add securitylockeddown() check to pcimmapresource()

Currently, Alpha's pcimmapresource() does not check securitylockeddown(LOCKDOWNPCIACCESS) before allowing userspace to mmap PCI BARs.

The generic version has had this check since commit eb627e17727e ("PCI: Lock down BAR access when the kernel is locked down") to prevent DMA attacks when the kernel is locked down.

Add the same check to Alpha's pcimmapresource().

Database specific
{
    "cna_assigner": "Linux",
    "osv_generated_from": "https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/80xxx/CVE-2026-80867.json"
}
References

Affected packages

Git / git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git

Affected ranges

Type
GIT
Repo
https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git
Events
Introduced
eb627e17727ebeede70697ae1798688b0d328b54
Fixed
6e368485a1ac19fbde0a8b6a332d4545ae72a8ac
Fixed
ed2cd1fee0ed16a1c2dff49175e65c641eb8ae2b
Fixed
c3234efe21d4198945492cf7dba6859476f0f6ff
Fixed
4de5ff924c0a8ef8166c1a68af9087826e1e8d61
Fixed
85f966b1120874fe530edec50d28373ceb06ebcd
Fixed
94defb18ac792fd16407d5a52ad0d3f5055c4b43
Fixed
257b55dc3d18d7ef01f62a8ff7317871f7597e28
Fixed
78a228f0aa0e9eba31955950c8a40a9945e2c8bb

Database specific

source
"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-80867.json"

Linux / Kernel

Package

Name
Kernel

Affected ranges

Type
ECOSYSTEM
Events
Introduced
5.4.0
Fixed
5.10.261
Type
ECOSYSTEM
Events
Introduced
5.11.0
Fixed
5.15.212
Type
ECOSYSTEM
Events
Introduced
5.16.0
Fixed
6.1.178
Type
ECOSYSTEM
Events
Introduced
6.2.0
Fixed
6.6.145
Type
ECOSYSTEM
Events
Introduced
6.7.0
Fixed
6.12.97
Type
ECOSYSTEM
Events
Introduced
6.13.0
Fixed
6.18.40
Type
ECOSYSTEM
Events
Introduced
6.19.0
Fixed
7.1.5

Database specific

source
"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-80867.json"