CVE-2026-80577
In the Linux kernel, the following vulnerability has been resolved:
drm/panthor: skip zero-sized firmware sections
panthor_fw_load_section_entry() skips BO creation when the firmware section VA range is empty. If such a section is added to the firmware section list, section->mem is left as NULL.
Later reload and unplug paths iterate over all firmware sections and dereference section->mem, which can lead to a NULL pointer dereference.
Zero-sized firmware sections are valid, so accept them as no-op entries but skip adding them to the section list.
CVSS
NVD no ha asignado puntuación CVSS a esta CVE (habitual desde el cambio de política de abril de 2026).
Probabilidad de explotación (EPSS)
- Probabilidad de explotación en los próximos 30 días: 0.21%
- Percentil entre todas las CVEs puntuadas: 10
- Fecha de la puntuación: 6/10/2026
EPSS (Exploit Prediction Scoring System, de FIRST) estima la probabilidad de que una vulnerabilidad sea explotada en 30 días. Complementa a CVSS (impacto) y a CISA KEV (explotación confirmada).
Tecnologías afectadas (1)
⚠ Inferidas por IA a partir de la descripción — NVD aún no ha analizado esta CVE; no son CPE verificados.
Referencias
JSON original (NVD)
Mostrar
{
"id": "CVE-2026-80577",
"cveTags": [],
"metrics": {},
"affected": [
{
"source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"affectedData": [
{
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"product": "Linux",
"versions": [
{
"status": "affected",
"version": "2718d91816eeed03c09c8abe872e45f59078768c",
"lessThan": "f0f3c3922db981031733a25c51e1f37cf9b9e251",
"versionType": "git"
},
{
"status": "affected",
"version": "2718d91816eeed03c09c8abe872e45f59078768c",
"lessThan": "25556a46ae6ecf2a9f1c1c5096828eecd4596b91",
"versionType": "git"
},
{
"status": "affected",
"version": "2718d91816eeed03c09c8abe872e45f59078768c",
"lessThan": "5d222b657f02a37f658e4e21925b85b4703855e7",
"versionType": "git"
},
{
"status": "affected",
"version": "2718d91816eeed03c09c8abe872e45f59078768c",
"lessThan": "2b8f13d3c7e26c46c20d9e367904cf01729c88e6",
"versionType": "git"
}
],
"programFiles": [
"drivers/gpu/drm/panthor/panthor_fw.c"
],
"defaultStatus": "unaffected"
},
{
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"product": "Linux",
"versions": [
{
"status": "affected",
"version": "6.10"
},
{
"status": "unaffected",
"version": "0",
"lessThan": "6.10",
"versionType": "semver"
},
{
"status": "unaffected",
"version": "6.12.105",
"versionType": "semver",
"lessThanOrEqual": "6.12.*"
},
{
"status": "unaffected",
"version": "6.18.46",
"versionType": "semver",
"lessThanOrEqual": "6.18.*"
},
{
"status": "unaffected",
"version": "7.1.10",
"versionType": "semver",
"lessThanOrEqual": "7.1.*"
},
{
"status": "unaffected",
"version": "7.2",
"versionType": "original_commit_for_fix",
"lessThanOrEqual": "*"
}
],
"programFiles": [
"drivers/gpu/drm/panthor/panthor_fw.c"
],
"defaultStatus": "affected"
}
]
}
],
"published": "2026-08-26T15:17:13.763",
"references": [
{
"url": "https://git.kernel.org/stable/c/25556a46ae6ecf2a9f1c1c5096828eecd4596b91",
"source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
},
{
"url": "https://git.kernel.org/stable/c/2b8f13d3c7e26c46c20d9e367904cf01729c88e6",
"source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
},
{
"url": "https://git.kernel.org/stable/c/5d222b657f02a37f658e4e21925b85b4703855e7",
"source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
},
{
"url": "https://git.kernel.org/stable/c/f0f3c3922db981031733a25c51e1f37cf9b9e251",
"source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
}
],
"vulnStatus": "Received",
"descriptions": [
{
"lang": "en",
"value": "In the Linux kernel, the following vulnerability has been resolved:\n\ndrm/panthor: skip zero-sized firmware sections\n\npanthor_fw_load_section_entry() skips BO creation when the firmware section\nVA range is empty. If such a section is added to the firmware section list,\nsection->mem is left as NULL.\n\nLater reload and unplug paths iterate over all firmware sections and\ndereference section->mem, which can lead to a NULL pointer dereference.\n\nZero-sized firmware sections are valid, so accept them as no-op entries but\nskip adding them to the section list."
}
],
"lastModified": "2026-08-26T15:17:13.763",
"sourceIdentifier": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
}