In the Linux kernel, the following vulnerability has been resolved:
drm/vmwgfx: drop dma_buf reference on foreign-fd prime import
ttmprimefdtohandle() returns -ENOSYS when the imported fd's dmabuf->ops do not match the ttmobjectdevice's ops, but does so without releasing the reference acquired by dmabufget(). Any unprivileged renderD client passing a non-vmwgfx prime fd through the DRMVMWGBSURFACE_REF{,EXT} path leaks one dmabuf reference per call and indefinitely pins the foreign exporter's GEM resources.
Funnel the error path through the existing dmabufput() so the reference is always dropped.
{
"cna_assigner": "Linux",
"osv_generated_from": "https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/80xxx/CVE-2026-80888.json"
}