PT-2026-83001 · Git+3 · Kernel+119

CVE-2026-80701

·

Published

2026-08-28

·

Updated

2026-08-28

CVSS v4.0

6.8

Medium

VectorAV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N
In the Linux kernel, the following vulnerability has been resolved:
drm/vmwgfx: enforce cursor size limits for MOB cursors
vmw cursor plane atomic check() bounds cursor width and height only on the legacy update path; the SVGA CAP2 CURSOR MOB path -- the default on modern hosts -- accepts any size. When the requested size exceeds SVGA REG CURSOR MAX DIMENSION or SVGA REG MOB MAX SIZE, vmw cursor mob get() returns -EINVAL and leaves vps->cursor.mob NULL. Its return value is then discarded in vmw cursor plane prepare fb(), so the subsequent vmw cursor update mob() calls vmw bo map and cache(NULL) and oopses inside vmw bo map and cache size() on the tbo.base.size load.
Reachable from any DRM master via DRM IOCTL MODE CURSOR2 with a sufficiently large width or height (e.g. cursor max dim + 1).
Reject oversized cursors in atomic check for both MOB-backed cursor update types. The MOB byte-size limit only applies to the SVGA CAP2 CURSOR MOB path (vmw cursor mob size() returns 0 for GB ONLY); compute the required MOB size in 64-bit to avoid overflow when very large dimensions are requested.
In prepare fb only call vmw cursor mob get()/ map() for VMW CURSOR UPDATE MOB -- the GB ONLY path uses bo->map.virtual directly and would otherwise be silently downgraded to NONE on hosts without SVGA CAP2 CURSOR MOB (where vmw cursor mob get() always returns -EINVAL). Degrade the update to NONE if vmw cursor mob get() or vmw cursor mob map() fails so the update path does not run with a NULL backing MOB.

Exploit

Fix

Found an issue in the description? Have something to add? Feel free to write us 👾

Related Identifiers

CVE-2026-80701

Affected Products

Kernel
Linux
Linux-Allwinner-5.19
Linux-Aws
Linux-Aws-5.0
Linux-Aws-5.11
Linux-Aws-5.13
Linux-Aws-5.19
Linux-Aws-5.3
Linux-Aws-5.8
Linux-Aws-6.14
Linux-Aws-6.17
Linux-Aws-6.2
Linux-Aws-6.5
Linux-Aws-7.0
Linux-Azure
Linux-Azure-5.11
Linux-Azure-5.13
Linux-Azure-5.19
Linux-Azure-5.3
Linux-Azure-5.8
Linux-Azure-6.11
Linux-Azure-6.14
Linux-Azure-6.17
Linux-Azure-6.2
Linux-Azure-6.5
Linux-Azure-7.0
Linux-Azure-Edge
Linux-Azure-Fde
Linux-Azure-Fde-5.19
Linux-Azure-Fde-6.14
Linux-Azure-Fde-6.17
Linux-Azure-Fde-6.2
Linux-Azure-Fde-7.0
Linux-Azure-Nvidia-6.14
Linux-Bluefield
Linux-Gcp
Linux-Gcp-5.11
Linux-Gcp-5.13
Linux-Gcp-5.19
Linux-Gcp-5.3
Linux-Gcp-5.8
Linux-Gcp-6.11
Linux-Gcp-6.14
Linux-Gcp-6.17
Linux-Gcp-6.2
Linux-Gcp-6.5
Linux-Gcp-7.0
Linux-Gke
Linux-Gke-4.15
Linux-Gkeop-5.15
Linux-Gke-5.4
Linux-Gkeop
Linux-Hwe
Linux-Hwe-5.11
Linux-Hwe-5.13
Linux-Hwe-5.19
Linux-Hwe-5.8
Linux-Hwe-6.11
Linux-Hwe-6.14
Linux-Hwe-6.17
Linux-Hwe-6.2
Linux-Hwe-6.5
Linux-Hwe-7.0
Linux-Hwe-Edge
Linux-Ibm
Linux-Intel-5.13
Linux-Intel-Iot-Realtime
Linux-Lowlatency-Hwe-5.19
Linux-Lowlatency-Hwe-6.11
Linux-Lowlatency-Hwe-6.2
Linux-Lowlatency-Hwe-6.5
Linux-Nvidia
Linux-Nvidia-6.11
Linux-Nvidia-6.17
Linux-Nvidia-6.2
Linux-Nvidia-6.5
Linux-Nvidia-7.0
Linux-Nvidia-Bos
Linux-Oem
Linux-Oem-5.10
Linux-Oem-5.13
Linux-Oem-5.14
Linux-Oem-5.17
Linux-Oem-5.6
Linux-Oem-6.0
Linux-Oem-6.1
Linux-Oem-6.11
Linux-Oem-6.14
Linux-Oem-6.17
Linux-Oem-6.5
Linux-Oem-6.8
Linux-Oem-7.0
Linux-Oracle
Linux-Oracle-5.0
Linux-Oracle-5.11
Linux-Oracle-5.13
Linux-Oracle-5.3
Linux-Oracle-5.8
Linux-Oracle-6.14
Linux-Oracle-6.17
Linux-Oracle-6.5
Linux-Oracle-7.0
Linux-Raspi
Linux-Raspi-Realtime
Linux-Raspi2
Linux-Realtime
Linux-Realtime-6.14
Linux-Realtime-6.17
Linux-Riscv
Linux-Riscv-5.11
Linux-Riscv-5.19
Linux-Riscv-5.8
Linux-Riscv-6.14
Linux-Riscv-6.17
Linux-Riscv-6.5
Linux-Riscv-7.0
Linux-Starfive-5.19
Linux-Starfive-6.2
Linux-Starfive-6.5