From mboxrd@z Thu Jan 1 00:00:00 1970 Received: from smtp.kernel.org (aws-us-west-2-korg-mail-alma10-1.taild15c8.ts.net [100.103.45.18]) (using TLSv1.2 with cipher ECDHE-RSA-AES256-GCM-SHA384 (256/256 bits)) (No client certificate requested) by smtp.subspace.kernel.org (Postfix) with ESMTPS id F121E4F30D5 for ; Fri, 4 Sep 2026 17:15:37 +0000 (UTC) Authentication-Results: smtp.subspace.kernel.org; arc=none smtp.client-ip=100.103.45.18 ARC-Seal:i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1788542139; cv=none; b=nxo4l7dVmExa25NvZ9x5r/2PU8EzDyI+oTUhlReVEXmR6FfPJ9zxdcMENTHWB/HeOyAEDRUNPQ4ylxduGDov+jY9ZtnzSM089tVbBRAtHRXzPjJKVDQIM1OtpsJ/xkAV/B3r/59rGVv4e2nW0vvTx7SBZZ5qwMAVP5jDdSvkvuM= ARC-Message-Signature:i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1788542139; c=relaxed/simple; bh=d/Mb7kiB/9598ZEUvG+0ZI4qdBK7vHQz9MhNk+G+2uk=; h=From:To:Cc:Subject:Date:Message-ID:MIME-Version; b=V+6XwkjtoMBrygdhUP8MryWPKpsgCnZzkm562HstiVimHkhgCIwq7rXAvZXaO6fj6pChE9BgDMepWx84LvHd8+gRdkjKJhzNbuzZtZQI79UWLeHRQg2dRFcxT9B+g+SLXws5DFvZOGIuSFBySAF2sRuSj67oiz/Z3M5wFOCv+20= ARC-Authentication-Results:i=1; smtp.subspace.kernel.org; dkim=pass (1024-bit key) header.d=linuxfoundation.org header.i=@linuxfoundation.org header.b=jm/WArCA; arc=none smtp.client-ip=100.103.45.18 Authentication-Results: smtp.subspace.kernel.org; dkim=pass (1024-bit key) header.d=linuxfoundation.org header.i=@linuxfoundation.org header.b="jm/WArCA" Received: by smtp.kernel.org (Postfix) with ESMTPSA id 7D2631F00A3D; Fri, 4 Sep 2026 17:15:36 +0000 (UTC) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=linuxfoundation.org; s=korg; t=1788542137; bh=FS9+tggKRR/EGJK3Ix3z1GA2phgTwwfLePoXRA8OppQ=; h=From:To:Cc:Subject:Date:Reply-To; b=jm/WArCAFGicDW1Yk83VMIBXlwdox92DGj8UpJewvv5ijFq/q0cc0xYy7fHeALnVE 03+EHdYUVjBKj8fNwjgTLiiAB+a1hCIOjN4SgB2Wa09Jn7XCGvxO8hD6hh+YgZQGXU 2huWD5MDcKO5T4RO0pcYHcRzTxlV4pp0Zjt8J6Fk= From: Greg Kroah-Hartman To: linux-cve-announce@vger.kernel.org Cc: Greg Kroah-Hartman Subject: CVE-2026-80888: drm/vmwgfx: drop dma_buf reference on foreign-fd prime import Date: Fri, 4 Sep 2026 19:09:29 +0200 Message-ID: <2026090429-CVE-2026-80888-dae5@gregkh> X-Mailer: git-send-email 2.55.0 Reply-To: , Precedence: bulk X-Mailing-List: linux-cve-announce@vger.kernel.org List-Id: List-Subscribe: List-Unsubscribe: MIME-Version: 1.0 X-Developer-Signature: v=1; a=openpgp-sha256; l=3193; i=gregkh@linuxfoundation.org; h=from:subject:message-id; bh=xSAgykfj+hxAjiUu0/Am2R1I0mFGvVwKEgvkcItMo7A=; b=owGbwMvMwCRo6H6F97bub03G02pJDFmzfnuKJa/esnb1Fa7XjPsTvE6m+9mZLghiuLevyE9Uq 8tkAwt/RywLgyATg6yYIsuXbTxH91ccUvQytD0NM4eVCWQIAxenAExkZwzDXOk3B+13+uwxWya4 N+K1/qIdp6/3rGKYX9nuVL2qJcXDeFmq1n/VjWEbTnGZAwA= X-Developer-Key: i=gregkh@linuxfoundation.org; a=openpgp; fpr=F4B60CC5BF78C2214A313DCB3147D40DDB2DFB29 Content-Transfer-Encoding: 8bit From: Greg Kroah-Hartman Description =========== In the Linux kernel, the following vulnerability has been resolved: drm/vmwgfx: drop dma_buf reference on foreign-fd prime import ttm_prime_fd_to_handle() returns -ENOSYS when the imported fd's dma_buf->ops do not match the ttm_object_device's ops, but does so without releasing the reference acquired by dma_buf_get(). Any unprivileged renderD client passing a non-vmwgfx prime fd through the DRM_VMW_GB_SURFACE_REF{,_EXT} path leaks one dma_buf reference per call and indefinitely pins the foreign exporter's GEM resources. Funnel the error path through the existing dma_buf_put() so the reference is always dropped. The Linux kernel CVE team has assigned CVE-2026-80888 to this issue. Affected and fixed versions =========================== Issue introduced in 3.13 with commit 65981f7681abdf92b25942222b629b9c512d0705 and fixed in 6.1.183 with commit 619c3cfa88e09603a13d918f754808db2dda7057 Issue introduced in 3.13 with commit 65981f7681abdf92b25942222b629b9c512d0705 and fixed in 6.6.151 with commit c1c22fca0a0896a452a7cb92422d67babd65b4be Issue introduced in 3.13 with commit 65981f7681abdf92b25942222b629b9c512d0705 and fixed in 6.12.103 with commit a1e972fa94c3a8069e022c67b9d97c7aa7b05293 Issue introduced in 3.13 with commit 65981f7681abdf92b25942222b629b9c512d0705 and fixed in 6.18.44 with commit a8434b145b1e467940334c58c00af241e9494c5f Issue introduced in 3.13 with commit 65981f7681abdf92b25942222b629b9c512d0705 and fixed in 7.1.8 with commit 4df39eb99bb47d1f24d1952c23b21b10988356bf Issue introduced in 3.13 with commit 65981f7681abdf92b25942222b629b9c512d0705 and fixed in 7.2 with commit f739416dc555fa205a785e5135d73fa39b26f35d Please see https://www.kernel.org for a full list of currently supported kernel versions by the kernel community. Unaffected versions might change over time as fixes are backported to older supported kernel versions. The official CVE entry at https://cve.org/CVERecord/?id=CVE-2026-80888 will be updated if fixes are backported, please check that for the most up to date information about this issue. Affected files ============== The file(s) affected by this issue are: drivers/gpu/drm/vmwgfx/ttm_object.c Mitigation ========== The Linux kernel CVE team recommends that you update to the latest stable kernel version for this, and many other bugfixes. Individual changes are never tested alone, but rather are part of a larger kernel release. Cherry-picking individual commits is not recommended or supported by the Linux kernel community at all. If however, updating to the latest release is impossible, the individual changes to resolve this issue can be found at these commits: https://git.kernel.org/stable/c/619c3cfa88e09603a13d918f754808db2dda7057 https://git.kernel.org/stable/c/c1c22fca0a0896a452a7cb92422d67babd65b4be https://git.kernel.org/stable/c/a1e972fa94c3a8069e022c67b9d97c7aa7b05293 https://git.kernel.org/stable/c/a8434b145b1e467940334c58c00af241e9494c5f https://git.kernel.org/stable/c/4df39eb99bb47d1f24d1952c23b21b10988356bf https://git.kernel.org/stable/c/f739416dc555fa205a785e5135d73fa39b26f35d