-

CVE-2026-80887

drm/vmwgfx: use check_add_overflow for shader size+offset bound

In the Linux kernel, the following vulnerability has been resolved:

drm/vmwgfx: use check_add_overflow for shader size+offset bound

vmw_shader_define() validates the user-supplied shader window against
its backing buffer with

	(u64)buffer->tbo.base.size < (u64)size + (u64)offset

drm_vmw_shader_create_arg::offset is __u64 in the uapi; when it is
near U64_MAX the unsigned addition wraps and the resulting tiny value
passes the check.  The unbounded offset is then stored in
res->guest_memory_offset and forwarded to host SVGA shader-create
commands.

Use check_add_overflow() to detect the wrap and compare the resulting
endpoint against the buffer size.
Daten sind bereitgestellt durch das CVE Programm von einer CVE Numbering Authority (CNA) (Unstrukturiert).
HerstellerLinux
≫
Produkt Linux
Default Statusunaffected
Version 668b206601c5f5063e03b76784a0d3024fa2b249
Version < 1bbe7751f5ebac383405ef29a66622d65bd505d3
Status affected
Version 668b206601c5f5063e03b76784a0d3024fa2b249
Version < d3f44438aa805270aaead3b6840ccaea0f4c11f9
Status affected
Version 668b206601c5f5063e03b76784a0d3024fa2b249
Version < cfd163169af3be56eaef113c680ea251f0d09189
Status affected
Version 668b206601c5f5063e03b76784a0d3024fa2b249
Version < 5c725901908eb1e52a16fc0e2373cb761df42d21
Status affected
Version 668b206601c5f5063e03b76784a0d3024fa2b249
Version < 54d56d5b42d2e4c72ba6e365e9774da90698aa22
Status affected
HerstellerLinux
≫
Produkt Linux
Default Statusaffected
Version 6.4
Status affected
Version 0
Version < 6.4
Status unaffected
Version <= 6.6.*
Version 6.6.151
Status unaffected
Version <= 6.12.*
Version 6.12.103
Status unaffected
Version <= 6.18.*
Version 6.18.44
Status unaffected
Version <= 7.1.*
Version 7.1.8
Status unaffected
Version <= *
Version 7.2
Status unaffected
VulnDex Vulnerability Enrichment
Diese Information steht angemeldeten Benutzern zur Verfügung. Login Login
Zu dieser CVE wurde keine Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 0.17% 0.063
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
Es wurden noch keine Informationen zu CWE veröffentlicht.
https://git.kernel.org/stable/c/1bbe7751f5ebac383405ef29a66622d65bd505d3
https://git.kernel.org/stable/c/d3f44438aa805270aaead3b6840ccaea0f4c11f9
https://git.kernel.org/stable/c/cfd163169af3be56eaef113c680ea251f0d09189
https://git.kernel.org/stable/c/5c725901908eb1e52a16fc0e2373cb761df42d21
https://git.kernel.org/stable/c/54d56d5b42d2e4c72ba6e365e9774da90698aa22