CVE-2026-80582

Summary

In the Linux kernel, the following vulnerability has been resolved:

drm/shmem_helper: Check VMA boundaries for PMD mappings

In the ->huge_fault handler do not install a PMD huge page mapping if the huge page exceeds the boundaries of the VMA.

All other ->huge_fault handlers have similar checks and the resulting mapping will trigger a VM_BUG_ON_VMA() if it ever reaches copy_pmd_range().

Affected Software

VendorProductVersion RangeStatus
LinuxLinuxfc3bbf34e643faa8678aabdc3810c60109f3435a < 12803e89a1e593fd1e784dfe7453f5e392ccaff2affected
LinuxLinuxfc3bbf34e643faa8678aabdc3810c60109f3435a < 617bbd08714857c1613d7c550d43a9092ec0fb97affected
LinuxLinux7.0affected
LinuxLinux0 < 7.0unaffected
LinuxLinux7.1.10 <= 7.1.*unaffected
LinuxLinux7.2 <= *unaffected

Weaknesses

References