Memory Copy Vulnerability in Linux Kernel Affecting vmwgfx Graphics Driver
CVE-2026-80700

Currently unrated

Key Information:

Vendor

Linux

Status
Vendor
CVE Published:
28 August 2026

What is CVE-2026-80700?

A vulnerability in the Linux kernel's vmwgfx graphics driver allows unsafe memory copy operations due to improper validation of caller-supplied offsets, strides, and heights. This flaw can lead to significant stability issues and potential security exploits if an attacker tricks a configured CRTC into submitting a crafted atomic commit on an imported framebuffer. The vulnerability stems from a lack of bounds checking, which can cause out-of-bounds memory access during external buffer copy operations. To mitigate the risk, it is essential to validate row-copy endpoints against each buffer object's size and reject invalid parameters such as zero or improperly sized strides.

Affected Version(s)

Linux 9a9716bbbf3dd6b6cbefba3abcc89af8b72631f4 < 4e0f669e2951b742239c6fe847fcc406fe78748d

Linux 50f1199250912568606b3778dc56646c10cb7b04

Linux 50f1199250912568606b3778dc56646c10cb7b04 < 042ca38779554687fc32b66a28328e0d9a36c58f

References

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.