CVE-2026-80700
Last modified
CVE-2026-80700 is a high-severity vulnerability rated 7.8/10 on the CVSS scale. In the Linux kernel, the following vulnerability has been resolved: drm/vmwgfx: validate external BO copy bounds for both stride paths vmw_external_bo_copy() trusts caller-supplied offsets, strides, and heights and operates on imported dma-buf vmaps: - The equal-stride memcpy() bound was clamped after subtracting the offsets from dst_size and src_size; an offset larger than the BO size wraps the unsigned subtraction to a huge value and the resulting memcpy() runs off the end of the vmap. dst_stride * height is also a u32 multiplication that can overflow. - The non-equal-stride row-by-row path had no bound at all. EPSS estimates a 0.17% chance of exploitation in the next 30 days.
Description
In the Linux kernel, the following vulnerability has been resolved: drm/vmwgfx: validate external BO copy bounds for both stride paths vmw_external_bo_copy() trusts caller-supplied offsets, strides, and heights and operates on imported dma-buf vmaps: - The equal-stride memcpy() bound was clamped after subtracting the offsets from dst_size and src_size; an offset larger than the BO size wraps the unsigned subtraction to a huge value and the resulting memcpy() runs off the end of the vmap. dst_stride * height is also a u32 multiplication that can overflow. - The non-equal-stride row-by-row path had no bound at all. The loop touches bytes through offset + (height - 1) * stride + width_in_bytes, with only a WARN_ON(dst_stride < width_in_bytes), and could likewise step past the end of either mapping. The offsets and strides are derived from STDU/SOU plane state, so a configured CRTC submitting a crafted atomic commit on an imported framebuffer can reach this path. Validate the exact row-copy endpoint against each BO's size up front using check_mul_overflow() and check_add_overflow(). Use the bulk memcpy() path only when width_in_bytes covers the whole stride; otherwise copy one row at a time so partial-row updates near the bottom of a framebuffer remain valid. Also reject zero strides and stride < width_in_bytes, both of which the row-by-row path cannot represent safely.
Metrics
Affected Software
Source: CNA advisory (CVE.org). NVD analysis pending.
| Vendor | Product | Versions |
|---|---|---|
| Linux | Linux | >= 9a9716bbbf3dd6b6cbefba3abcc89af8b72631f4, < 4e0f669e2951b742239c6fe847fcc406fe78748d; >= 50f1199250912568606b3778dc56646c10cb7b04, < e7b25a6011781ebfdbc458552cae6d4156732771; >= 50f1199250912568606b3778dc56646c10cb7b04, < 042ca38779554687fc32b66a28328e0d9a36c58f; >= 50f1199250912568606b3778dc56646c10cb7b04, < 5e4a2d15637a906cbd9bc98e0bf969f5f713e344; >= 50f1199250912568606b3778dc56646c10cb7b04, < 706c93c5813caabbb0d0a576c017d15aeec2c113; 5c12391ee1ab59cb2f3be3f1f5e6d0fc0c2dc854; >= 6.6.49, < 6.6.151; >= 6.10.8, < 6.11 |
| Linux | Linux | 6.11 |
References
Timeline
- Published
- Last Modified
- Status
- Received
Frequently Asked Questions
What is CVE-2026-80700?
How severe is CVE-2026-80700?
How do I fix CVE-2026-80700?
How Strix Helps
- How Strix found a critical auth bypass in etcdStrix autonomously discovered a critical authentication bypass in etcd, later designated CVE-2026-33413.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2026
- CVE-2026-80695In the Linux kernel, the following vulnerability has been re…
- CVE-2026-80696In the Linux kernel, the following vulnerability has been re…7.8
- CVE-2026-80697In the Linux kernel, the following vulnerability has been re…
- CVE-2026-80698In the Linux kernel, the following vulnerability has been re…
- CVE-2026-80699In the Linux kernel, the following vulnerability has been re…
- CVE-2026-8070Incorrect permission assignment for a critical resource in A…7.3
- CVE-2026-80701In the Linux kernel, the following vulnerability has been re…
- CVE-2026-80702In the Linux kernel, the following vulnerability has been re…7.8
- CVE-2026-80703In the Linux kernel, the following vulnerability has been re…
- CVE-2026-80704In the Linux kernel, the following vulnerability has been re…
- CVE-2026-80705In the Linux kernel, the following vulnerability has been re…
- CVE-2026-80706In the Linux kernel, the following vulnerability has been re…7.8
Are you affected by CVE-2026-80700?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
