Junglewise Threat Intelligence

CVE-2026-80741: Linux kernel out-of-bounds read in DRM log message handler

CVE-2026-80741 · Severity: high · CVSS 7.1 · Published 2026-09-03

Technologies: Linux Kernel. Vendors: Linux.

Executive brief

The Linux kernel's display driver (DRM) logging component contains a bug in how it processes messages when rendering them to the console. When a message has a length of zero, the code attempts to access memory outside valid bounds, potentially exposing sensitive kernel data or causing a system crash.

Technical details

The vulnerability is an out-of-bounds read in the `drm_log_draw_kmsg_record()` function in `drivers/gpu/drm/clients/drm_log.c`. The function attempts to access `s[len - 1]` to remove a trailing newline, but `len` is an unsigned integer. When `len` is 0, the subtraction wraps around to UINT_MAX (4294967295), causing an out-of-bounds read of kernel memory. The fix adds an early return condition that checks if `len` is 0 before attempting the array access. This is a local attack that requires the ability to trigger DRM logging with an empty message, but the impact is memory disclosure or kernel crash.

Affected products

  • Linux Linux kernel Multiple versions through 2026

Timeline

  • 2026-09-03: disclosed
  • 2026-08-23: patched

References

Related threats