CVE-2026-80888

Source
https://cve.org/CVERecord?id=CVE-2026-80888
Import Source
https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-80888.json
JSON Data
https://api.osv.dev/v1/vulns/CVE-2026-80888
Downstream
Published
2026-09-04T17:11:04.975Z
Modified
2026-09-06T03:46:55.266227561Z
Summary
drm/vmwgfx: drop dma_buf reference on foreign-fd prime import
Details

In the Linux kernel, the following vulnerability has been resolved:

drm/vmwgfx: drop dma_buf reference on foreign-fd prime import

ttmprimefdtohandle() returns -ENOSYS when the imported fd's dmabuf->ops do not match the ttmobjectdevice's ops, but does so without releasing the reference acquired by dmabufget(). Any unprivileged renderD client passing a non-vmwgfx prime fd through the DRMVMWGBSURFACE_REF{,EXT} path leaks one dmabuf reference per call and indefinitely pins the foreign exporter's GEM resources.

Funnel the error path through the existing dmabufput() so the reference is always dropped.

Database specific
{
    "cna_assigner": "Linux",
    "osv_generated_from": "https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/80xxx/CVE-2026-80888.json"
}
References

Affected packages

Git / git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git

Affected ranges

Type
GIT
Repo
https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git
Events
Introduced
65981f7681abdf92b25942222b629b9c512d0705
Fixed
619c3cfa88e09603a13d918f754808db2dda7057
Fixed
c1c22fca0a0896a452a7cb92422d67babd65b4be
Fixed
a1e972fa94c3a8069e022c67b9d97c7aa7b05293
Fixed
a8434b145b1e467940334c58c00af241e9494c5f
Fixed
4df39eb99bb47d1f24d1952c23b21b10988356bf
Fixed
f739416dc555fa205a785e5135d73fa39b26f35d

Database specific

source
"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-80888.json"

Linux / Kernel

Package

Name
Kernel

Affected ranges

Type
ECOSYSTEM
Events
Introduced
3.13.0
Fixed
6.1.183
Type
ECOSYSTEM
Events
Introduced
6.2.0
Fixed
6.6.151
Type
ECOSYSTEM
Events
Introduced
6.7.0
Fixed
6.12.103
Type
ECOSYSTEM
Events
Introduced
6.13.0
Fixed
6.18.44
Type
ECOSYSTEM
Events
Introduced
6.19.0
Fixed
7.1.8

Database specific

source
"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-80888.json"