7.8

CVE-2026-80700

drm/vmwgfx: validate external BO copy bounds for both stride paths

In the Linux kernel, the following vulnerability has been resolved:

drm/vmwgfx: validate external BO copy bounds for both stride paths

vmw_external_bo_copy() trusts caller-supplied offsets, strides, and
heights and operates on imported dma-buf vmaps:

  - The equal-stride memcpy() bound was clamped after subtracting the
    offsets from dst_size and src_size; an offset larger than the BO
    size wraps the unsigned subtraction to a huge value and the
    resulting memcpy() runs off the end of the vmap.  dst_stride *
    height is also a u32 multiplication that can overflow.
  - The non-equal-stride row-by-row path had no bound at all.  The
    loop touches bytes through offset + (height - 1) * stride +
    width_in_bytes, with only a WARN_ON(dst_stride < width_in_bytes),
    and could likewise step past the end of either mapping.

The offsets and strides are derived from STDU/SOU plane state, so a
configured CRTC submitting a crafted atomic commit on an imported
framebuffer can reach this path.

Validate the exact row-copy endpoint against each BO's size up front
using check_mul_overflow() and check_add_overflow().  Use the bulk
memcpy() path only when width_in_bytes covers the whole stride;
otherwise copy one row at a time so partial-row updates near the bottom
of a framebuffer remain valid.  Also reject zero strides and stride <
width_in_bytes, both of which the row-by-row path cannot represent
safely.
Daten sind bereitgestellt durch das CVE Programm von einer CVE Numbering Authority (CNA) (Unstrukturiert).
HerstellerLinux
≫
Produkt Linux
Default Statusunaffected
Version 9a9716bbbf3dd6b6cbefba3abcc89af8b72631f4
Version < 4e0f669e2951b742239c6fe847fcc406fe78748d
Status affected
Version 50f1199250912568606b3778dc56646c10cb7b04
Version < e7b25a6011781ebfdbc458552cae6d4156732771
Status affected
Version 50f1199250912568606b3778dc56646c10cb7b04
Version < 042ca38779554687fc32b66a28328e0d9a36c58f
Status affected
Version 50f1199250912568606b3778dc56646c10cb7b04
Version < 5e4a2d15637a906cbd9bc98e0bf969f5f713e344
Status affected
Version 50f1199250912568606b3778dc56646c10cb7b04
Version < 706c93c5813caabbb0d0a576c017d15aeec2c113
Status affected
Version 5c12391ee1ab59cb2f3be3f1f5e6d0fc0c2dc854
Status affected
Version 6.6.49
Version < 6.6.151
Status affected
Version 6.10.8
Version < 6.11
Status affected
HerstellerLinux
≫
Produkt Linux
Default Statusaffected
Version 6.11
Status affected
Version 0
Version < 6.11
Status unaffected
Version <= 6.6.*
Version 6.6.151
Status unaffected
Version <= 6.12.*
Version 6.12.103
Status unaffected
Version <= 6.18.*
Version 6.18.44
Status unaffected
Version <= 7.1.*
Version 7.1.8
Status unaffected
Version <= *
Version 7.2
Status unaffected
VulnDex Vulnerability Enrichment
Diese Information steht angemeldeten Benutzern zur Verfügung. Login Login
Zu dieser CVE wurde keine Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 0.13% 0.028
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
416baaa9-dc9f-4396-8d5f-8c081fb06d67 7.8 1.8 5.9
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Es wurden noch keine Informationen zu CWE veröffentlicht.
https://git.kernel.org/stable/c/4e0f669e2951b742239c6fe847fcc406fe78748d
https://git.kernel.org/stable/c/e7b25a6011781ebfdbc458552cae6d4156732771
https://git.kernel.org/stable/c/042ca38779554687fc32b66a28328e0d9a36c58f
https://git.kernel.org/stable/c/5e4a2d15637a906cbd9bc98e0bf969f5f713e344
https://git.kernel.org/stable/c/706c93c5813caabbb0d0a576c017d15aeec2c113