« Volver al listado

CVE-2026-80700

Estado: RecibidaAlta (7.8)—

In the Linux kernel, the following vulnerability has been resolved:

drm/vmwgfx: validate external BO copy bounds for both stride paths

vmw_external_bo_copy() trusts caller-supplied offsets, strides, and heights and operates on imported dma-buf vmaps:

The offsets and strides are derived from STDU/SOU plane state, so a configured CRTC submitting a crafted atomic commit on an imported framebuffer can reach this path.

Validate the exact row-copy endpoint against each BO's size up front using check_mul_overflow() and check_add_overflow().

Leer descripción completaMostrar menos

Use the bulk memcpy() path only when width_in_bytes covers the whole stride; otherwise copy one row at a time so partial-row updates near the bottom of a framebuffer remain valid. Also reject zero strides and stride < width_in_bytes, both of which the row-by-row path cannot represent safely.

Detalles técnicos trazas, registros y código del informe original
  - The equal-stride memcpy() bound was clamped after subtracting the
    offsets from dst_size and src_size; an offset larger than the BO
    size wraps the unsigned subtraction to a huge value and the
    resulting memcpy() runs off the end of the vmap.  dst_stride *
    height is also a u32 multiplication that can overflow.
  - The non-equal-stride row-by-row path had no bound at all.  The
    loop touches bytes through offset + (height - 1) * stride +
    width_in_bytes, with only a WARN_ON(dst_stride < width_in_bytes),
    and could likewise step past the end of either mapping.

CVSS

Probabilidad de explotación (EPSS)

EPSS (Exploit Prediction Scoring System, de FIRST) estima la probabilidad de que una vulnerabilidad sea explotada en 30 días. Complementa a CVSS (impacto) y a CISA KEV (explotación confirmada).

🎯 Técnicas ATT&CK

Cómo se explota esta vulnerabilidad y qué consigue el atacante, en el lenguaje de MITRE ATT&CK.

Acceso local (AV:L) sin interacción en kernel Linux permite escalada de privilegios (PR:L→root) mediante buffer overflow en vmw_external_bo_copy() con offsets/strides manipulados en commit atómico de CRTC.

Inferido por nuestro agente de análisis a partir de la descripción oficial, el vector CVSS y la CWE, y comprobado por un supervisor. Puede contener errores.

🛡️ Mitigaciones ATT&CK que cubren estas técnicas

Tecnologías afectadas (1)

⚠ Inferidas por IA a partir de la descripción — NVD aún no ha analizado esta CVE; no son CPE verificados.

Referencias

JSON original (NVD)

Mostrar
{
  "id": "CVE-2026-80700",
  "cveTags": [],
  "metrics": {
    "cvssMetricV31": [
      {
        "type": "Secondary",
        "source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
        "cvssData": {
          "scope": "UNCHANGED",
          "version": "3.1",
          "baseScore": 7.8,
          "attackVector": "LOCAL",
          "baseSeverity": "HIGH",
          "vectorString": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H",
          "integrityImpact": "HIGH",
          "userInteraction": "NONE",
          "attackComplexity": "LOW",
          "availabilityImpact": "HIGH",
          "privilegesRequired": "LOW",
          "confidentialityImpact": "HIGH"
        },
        "impactScore": 5.9,
        "exploitabilityScore": 1.8
      }
    ]
  },
  "affected": [
    {
      "source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
      "affectedData": [
        {
          "repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
          "vendor": "Linux",
          "product": "Linux",
          "versions": [
            {
              "status": "affected",
              "version": "9a9716bbbf3dd6b6cbefba3abcc89af8b72631f4",
              "lessThan": "4e0f669e2951b742239c6fe847fcc406fe78748d",
              "versionType": "git"
            },
            {
              "status": "affected",
              "version": "50f1199250912568606b3778dc56646c10cb7b04",
              "lessThan": "e7b25a6011781ebfdbc458552cae6d4156732771",
              "versionType": "git"
            },
            {
              "status": "affected",
              "version": "50f1199250912568606b3778dc56646c10cb7b04",
              "lessThan": "042ca38779554687fc32b66a28328e0d9a36c58f",
              "versionType": "git"
            },
            {
              "status": "affected",
              "version": "50f1199250912568606b3778dc56646c10cb7b04",
              "lessThan": "5e4a2d15637a906cbd9bc98e0bf969f5f713e344",
              "versionType": "git"
            },
            {
              "status": "affected",
              "version": "50f1199250912568606b3778dc56646c10cb7b04",
              "lessThan": "706c93c5813caabbb0d0a576c017d15aeec2c113",
              "versionType": "git"
            },
            {
              "status": "affected",
              "version": "5c12391ee1ab59cb2f3be3f1f5e6d0fc0c2dc854",
              "versionType": "git"
            },
            {
              "status": "affected",
              "version": "6.6.49",
              "lessThan": "6.6.151",
              "versionType": "semver"
            },
            {
              "status": "affected",
              "version": "6.10.8",
              "lessThan": "6.11",
              "versionType": "semver"
            }
          ],
          "programFiles": [
            "drivers/gpu/drm/vmwgfx/vmwgfx_blit.c"
          ],
          "defaultStatus": "unaffected"
        },
        {
          "repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
          "vendor": "Linux",
          "product": "Linux",
          "versions": [
            {
              "status": "affected",
              "version": "6.11"
            },
            {
              "status": "unaffected",
              "version": "0",
              "lessThan": "6.11",
              "versionType": "semver"
            },
            {
              "status": "unaffected",
              "version": "6.6.151",
              "versionType": "semver",
              "lessThanOrEqual": "6.6.*"
            },
            {
              "status": "unaffected",
              "version": "6.12.103",
              "versionType": "semver",
              "lessThanOrEqual": "6.12.*"
            },
            {
              "status": "unaffected",
              "version": "6.18.44",
              "versionType": "semver",
              "lessThanOrEqual": "6.18.*"
            },
            {
              "status": "unaffected",
              "version": "7.1.8",
              "versionType": "semver",
              "lessThanOrEqual": "7.1.*"
            },
            {
              "status": "unaffected",
              "version": "7.2",
              "versionType": "original_commit_for_fix",
              "lessThanOrEqual": "*"
            }
          ],
          "programFiles": [
            "drivers/gpu/drm/vmwgfx/vmwgfx_blit.c"
          ],
          "defaultStatus": "affected"
        }
      ]
    }
  ],
  "published": "2026-08-28T08:16:55.517",
  "references": [
    {
      "url": "https://git.kernel.org/stable/c/042ca38779554687fc32b66a28328e0d9a36c58f",
      "source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
    },
    {
      "url": "https://git.kernel.org/stable/c/4e0f669e2951b742239c6fe847fcc406fe78748d",
      "source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
    },
    {
      "url": "https://git.kernel.org/stable/c/5e4a2d15637a906cbd9bc98e0bf969f5f713e344",
      "source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
    },
    {
      "url": "https://git.kernel.org/stable/c/706c93c5813caabbb0d0a576c017d15aeec2c113",
      "source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
    },
    {
      "url": "https://git.kernel.org/stable/c/e7b25a6011781ebfdbc458552cae6d4156732771",
      "source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
    }
  ],
  "vulnStatus": "Received",
  "descriptions": [
    {
      "lang": "en",
      "value": "In the Linux kernel, the following vulnerability has been resolved:\n\ndrm/vmwgfx: validate external BO copy bounds for both stride paths\n\nvmw_external_bo_copy() trusts caller-supplied offsets, strides, and\nheights and operates on imported dma-buf vmaps:\n\n  - The equal-stride memcpy() bound was clamped after subtracting the\n    offsets from dst_size and src_size; an offset larger than the BO\n    size wraps the unsigned subtraction to a huge value and the\n    resulting memcpy() runs off the end of the vmap.  dst_stride *\n    height is also a u32 multiplication that can overflow.\n  - The non-equal-stride row-by-row path had no bound at all.  The\n    loop touches bytes through offset + (height - 1) * stride +\n    width_in_bytes, with only a WARN_ON(dst_stride < width_in_bytes),\n    and could likewise step past the end of either mapping.\n\nThe offsets and strides are derived from STDU/SOU plane state, so a\nconfigured CRTC submitting a crafted atomic commit on an imported\nframebuffer can reach this path.\n\nValidate the exact row-copy endpoint against each BO's size up front\nusing check_mul_overflow() and check_add_overflow().  Use the bulk\nmemcpy() path only when width_in_bytes covers the whole stride;\notherwise copy one row at a time so partial-row updates near the bottom\nof a framebuffer remain valid.  Also reject zero strides and stride <\nwidth_in_bytes, both of which the row-by-row path cannot represent\nsafely."
    }
  ],
  "lastModified": "2026-08-29T07:16:51.807",
  "sourceIdentifier": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
}