PT-2026-83001 · Git+3 · Kernel+119
CVE-2026-80701
·
Published
2026-08-28
·
Updated
2026-08-28
CVSS v4.0
6.8
Medium
| Vector | AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N |
In the Linux kernel, the following vulnerability has been resolved:
drm/vmwgfx: enforce cursor size limits for MOB cursors
vmw cursor plane atomic check() bounds cursor width and height only
on the legacy update path; the SVGA CAP2 CURSOR MOB path -- the
default on modern hosts -- accepts any size. When the requested size
exceeds SVGA REG CURSOR MAX DIMENSION or SVGA REG MOB MAX SIZE,
vmw cursor mob get() returns -EINVAL and leaves vps->cursor.mob NULL.
Its return value is then discarded in vmw cursor plane prepare fb(),
so the subsequent vmw cursor update mob() calls
vmw bo map and cache(NULL) and oopses inside
vmw bo map and cache size() on the tbo.base.size load.
Reachable from any DRM master via DRM IOCTL MODE CURSOR2 with a
sufficiently large width or height (e.g. cursor max dim + 1).
Reject oversized cursors in atomic check for both MOB-backed cursor
update types. The MOB byte-size limit only applies to the
SVGA CAP2 CURSOR MOB path (vmw cursor mob size() returns 0 for
GB ONLY); compute the required MOB size in 64-bit to avoid overflow
when very large dimensions are requested.
In prepare fb only call vmw cursor mob get()/ map() for
VMW CURSOR UPDATE MOB -- the GB ONLY path uses bo->map.virtual
directly and would otherwise be silently downgraded to NONE on hosts
without SVGA CAP2 CURSOR MOB (where vmw cursor mob get() always
returns -EINVAL). Degrade the update to NONE if vmw cursor mob get()
or vmw cursor mob map() fails so the update path does not run with a
NULL backing MOB.
Exploit
Fix
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Kernel
Linux
Linux-Allwinner-5.19
Linux-Aws
Linux-Aws-5.0
Linux-Aws-5.11
Linux-Aws-5.13
Linux-Aws-5.19
Linux-Aws-5.3
Linux-Aws-5.8
Linux-Aws-6.14
Linux-Aws-6.17
Linux-Aws-6.2
Linux-Aws-6.5
Linux-Aws-7.0
Linux-Azure
Linux-Azure-5.11
Linux-Azure-5.13
Linux-Azure-5.19
Linux-Azure-5.3
Linux-Azure-5.8
Linux-Azure-6.11
Linux-Azure-6.14
Linux-Azure-6.17
Linux-Azure-6.2
Linux-Azure-6.5
Linux-Azure-7.0
Linux-Azure-Edge
Linux-Azure-Fde
Linux-Azure-Fde-5.19
Linux-Azure-Fde-6.14
Linux-Azure-Fde-6.17
Linux-Azure-Fde-6.2
Linux-Azure-Fde-7.0
Linux-Azure-Nvidia-6.14
Linux-Bluefield
Linux-Gcp
Linux-Gcp-5.11
Linux-Gcp-5.13
Linux-Gcp-5.19
Linux-Gcp-5.3
Linux-Gcp-5.8
Linux-Gcp-6.11
Linux-Gcp-6.14
Linux-Gcp-6.17
Linux-Gcp-6.2
Linux-Gcp-6.5
Linux-Gcp-7.0
Linux-Gke
Linux-Gke-4.15
Linux-Gkeop-5.15
Linux-Gke-5.4
Linux-Gkeop
Linux-Hwe
Linux-Hwe-5.11
Linux-Hwe-5.13
Linux-Hwe-5.19
Linux-Hwe-5.8
Linux-Hwe-6.11
Linux-Hwe-6.14
Linux-Hwe-6.17
Linux-Hwe-6.2
Linux-Hwe-6.5
Linux-Hwe-7.0
Linux-Hwe-Edge
Linux-Ibm
Linux-Intel-5.13
Linux-Intel-Iot-Realtime
Linux-Lowlatency-Hwe-5.19
Linux-Lowlatency-Hwe-6.11
Linux-Lowlatency-Hwe-6.2
Linux-Lowlatency-Hwe-6.5
Linux-Nvidia
Linux-Nvidia-6.11
Linux-Nvidia-6.17
Linux-Nvidia-6.2
Linux-Nvidia-6.5
Linux-Nvidia-7.0
Linux-Nvidia-Bos
Linux-Oem
Linux-Oem-5.10
Linux-Oem-5.13
Linux-Oem-5.14
Linux-Oem-5.17
Linux-Oem-5.6
Linux-Oem-6.0
Linux-Oem-6.1
Linux-Oem-6.11
Linux-Oem-6.14
Linux-Oem-6.17
Linux-Oem-6.5
Linux-Oem-6.8
Linux-Oem-7.0
Linux-Oracle
Linux-Oracle-5.0
Linux-Oracle-5.11
Linux-Oracle-5.13
Linux-Oracle-5.3
Linux-Oracle-5.8
Linux-Oracle-6.14
Linux-Oracle-6.17
Linux-Oracle-6.5
Linux-Oracle-7.0
Linux-Raspi
Linux-Raspi-Realtime
Linux-Raspi2
Linux-Realtime
Linux-Realtime-6.14
Linux-Realtime-6.17
Linux-Riscv
Linux-Riscv-5.11
Linux-Riscv-5.19
Linux-Riscv-5.8
Linux-Riscv-6.14
Linux-Riscv-6.17
Linux-Riscv-6.5
Linux-Riscv-7.0
Linux-Starfive-5.19
Linux-Starfive-6.2
Linux-Starfive-6.5