drm/vmwgfx: drop dma_buf reference on foreign-fd prime import

Summary

CVECVE-2026-80888
StatePUBLISHED
AssignerLinux
Source PriorityCVE Program / NVD first with legacy fallback
Published2026-09-04 18:17:56 UTC
Updated2026-09-04 18:17:56 UTC
DescriptionIn the Linux kernel, the following vulnerability has been resolved: drm/vmwgfx: drop dma_buf reference on foreign-fd prime import ttm_prime_fd_to_handle() returns -ENOSYS when the imported fd's dma_buf->ops do not match the ttm_object_device's ops, but does so without releasing the reference acquired by dma_buf_get(). Any unprivileged renderD client passing a non-vmwgfx prime fd through the DRM_VMW_GB_SURFACE_REF{,_EXT} path leaks one dma_buf reference per call and indefinitely pins the foreign exporter's GEM resources. Funnel the error path through the existing dma_buf_put() so the reference is always dropped.

Risk And Classification

EPSS: 0.001730000 probability, percentile 0.068830000 (date 2026-09-07)

Vendor Declared Affected Products

SourceVendorProductVersionPlatforms
CNA Linux Linux affected 65981f7681abdf92b25942222b629b9c512d0705 619c3cfa88e09603a13d918f754808db2dda7057 git Not specified
CNA Linux Linux affected 65981f7681abdf92b25942222b629b9c512d0705 c1c22fca0a0896a452a7cb92422d67babd65b4be git Not specified
CNA Linux Linux affected 65981f7681abdf92b25942222b629b9c512d0705 a1e972fa94c3a8069e022c67b9d97c7aa7b05293 git Not specified
CNA Linux Linux affected 65981f7681abdf92b25942222b629b9c512d0705 a8434b145b1e467940334c58c00af241e9494c5f git Not specified
CNA Linux Linux affected 65981f7681abdf92b25942222b629b9c512d0705 4df39eb99bb47d1f24d1952c23b21b10988356bf git Not specified
CNA Linux Linux affected 65981f7681abdf92b25942222b629b9c512d0705 f739416dc555fa205a785e5135d73fa39b26f35d git Not specified
CNA Linux Linux affected 3.13 Not specified
CNA Linux Linux unaffected 3.13 semver Not specified
CNA Linux Linux unaffected 6.1.183 6.1.* semver Not specified
CNA Linux Linux unaffected 6.6.151 6.6.* semver Not specified
CNA Linux Linux unaffected 6.12.103 6.12.* semver Not specified
CNA Linux Linux unaffected 6.18.44 6.18.* semver Not specified
CNA Linux Linux unaffected 7.1.8 7.1.* semver Not specified
CNA Linux Linux unaffected 7.2 * original_commit_for_fix Not specified

References

ReferenceSourceLinkTags
git.kernel.org/stable/c/619c3cfa88e09603a13d918f754808db2dda7057 416baaa9-dc9f-4396-8d5f-8c081fb06d67 git.kernel.org
git.kernel.org/stable/c/4df39eb99bb47d1f24d1952c23b21b10988356bf 416baaa9-dc9f-4396-8d5f-8c081fb06d67 git.kernel.org
git.kernel.org/stable/c/a8434b145b1e467940334c58c00af241e9494c5f 416baaa9-dc9f-4396-8d5f-8c081fb06d67 git.kernel.org
git.kernel.org/stable/c/f739416dc555fa205a785e5135d73fa39b26f35d 416baaa9-dc9f-4396-8d5f-8c081fb06d67 git.kernel.org
git.kernel.org/stable/c/c1c22fca0a0896a452a7cb92422d67babd65b4be 416baaa9-dc9f-4396-8d5f-8c081fb06d67 git.kernel.org
git.kernel.org/stable/c/a1e972fa94c3a8069e022c67b9d97c7aa7b05293 416baaa9-dc9f-4396-8d5f-8c081fb06d67 git.kernel.org
CVE Program record CVE.ORG www.cve.org canonical
NVD vulnerability detail NVD nvd.nist.gov canonical, analysis

© CVE.report 2026

Use of this information constitutes acceptance for use in an AS IS condition. There are NO warranties, implied or otherwise, with regard to this information or its use. Any use of this information is at the user's risk. It is the responsibility of user to evaluate the accuracy, completeness or usefulness of any information, opinion, advice or other content. EACH USER WILL BE SOLELY RESPONSIBLE FOR ANY consequences of his or her direct or indirect use of this web site. ALL WARRANTIES OF ANY KIND ARE EXPRESSLY DISCLAIMED. This site will NOT BE LIABLE FOR ANY DIRECT, INDIRECT or any other kind of loss.

CVE, CWE, and OVAL are registred trademarks of The MITRE Corporation and the authoritative source of CVE content is MITRE's CVE web site. This site includes MITRE data granted under the following license.

Free CVE JSON API cve.report/api

CVE.report and Source URL Uptime Status status.cve.report