Answer in brief
CVE-2026-80541 records a Unknown severity vulnerability in drm/amdgpu: validate GEM_CREATE domain combinations. The current sources do not mark it as known exploited. The current feed maps Linux/Linux (generic). Check affected ranges and fixed versions before updating.
Analysis pending evidence review
HOL Guard separates source facts from reviewed analysis. See the methodology.
A CVSS score is not reported in the current record. The current sources do not mark it as known exploited. Treat this as a source-backed prioritization signal, not a statement about your environment.
Analysis status
Analysis pending evidence review
Factual feed record only; HOL analysis is not approved for indexing. Read the methodology.
The current feed maps Linux/Linux (generic). Check affected ranges and fixed versions before updating.
| Package | Affected range | Fixed version |
|---|---|---|
| Linux/Linuxgeneric | >=1da177e4c3f41524e886b7f1b8a0c1fc7321cac2 <5c73485af7ad9c3ae592db3481f370bc07705391 || >=1da177e4c3f41524e886b7f1b8a0c1fc7321cac2 <584e3d47736fe2e7184ef3fc16b00b41485f96c6 || >=1da177e4c3f41524e886b7f1b8a0c1fc7321cac2 <66133fc05c3af002f45de8a71b833c026ccbfba6 || >=1da177e4c3f41524e886b7f1b8a0c1fc7321cac2 <ce5da474c3ddf7cccec5dce6aa4296297dd7caff || >=1da177e4c3f41524e886b7f1b8a0c1fc7321cac2 <493355096e397f9217b41c8574ed2784c7351443 || >=1da177e4c3f41524e886b7f1b8a0c1fc7321cac2 <220aa2589d7321fb68d2e8597862711b5f22ae0b || >=1da177e4c3f41524e886b7f1b8a0c1fc7321cac2 <80f0b53860d02577709d69a312a29ca674b9297c || >=1da177e4c3f41524e886b7f1b8a0c1fc7321cac2 <5e9d136ad74df4edec67e502ce267597064d8f86 || >=0 <5.10.266 || >=0 <5.15.217 || >=0 <6.1.184 || >=0 <6.6.153 || >=0 <6.12.105 || >=0 <6.18.46 || >=0 <7.1.10 | 5c73485af7ad9c3ae592db3481f370bc07705391, 584e3d47736fe2e7184ef3fc16b00b41485f96c6, 66133fc05c3af002f45de8a71b833c026ccbfba6, ce5da474c3ddf7cccec5dce6aa4296297dd7caff, 493355096e397f9217b41c8574ed2784c7351443, 220aa2589d7321fb68d2e8597862711b5f22ae0b, 80f0b53860d02577709d69a312a29ca674b9297c, 5e9d136ad74df4edec67e502ce267597064d8f86, 5.10.266, 5.15.217, 6.1.184, 6.6.153, 6.12.105, 6.18.46, 7.1.10 |
Published upstream
Aug 26, 2026
Evidence: source:cvelist:source_dates:source-dates:recordSource modified
Aug 26, 2026
Evidence: source:cvelist:source_dates:source-dates:recordFirst seen by HOL
Aug 26, 2026
In the Linux kernel, the following vulnerability has been resolved: drm/amdgpu: validate GEM_CREATE domain combinations AMDGPU_GEM_CREATE checked domain bits against AMDGPU_GEM_DOMAIN_MASK, but did not validate domain combinations. Userspace could combine CPU|GTT|VRAM with DOORBELL, GDS, GWS, or OA, making amdgpu_bo_placement_from_domain() exceed AMDGPU_BO_MAX_PLACEMENTS and hit BUG_ON(). Allow combinations only within CPU/GTT/VRAM, and require non-CPU/GTT/ VRAM domains to be specified one at a time. Return -EINVAL for invalid combinations in amdgpu_gem_create_ioctl(). v2: Rename helper from amdgpu_gem_domain_valid() to amdgpu_gem_are_domains_valid() (Christian) (cherry picked from commit db39852d0c39843cb02048dfb47e4b8c703e9080)
Quoted source text, attributed separately from HOL analysis.