CVE-2026-80867: Linux

EPSS: 0.2% chance of exploitation in the next 30 days.

In the Linux kernel, the following vulnerability has been resolved: alpha/PCI: Add security_locked_down() check to pci_mmap_resource() Currently, Alpha's pci_mmap_resource() does not check security_locked_down(LOCKDOWN_PCI_ACCESS) before allowing userspace to mmap PCI BARs. The generic version has had this check since commit eb627e17727e ("PCI: Lock down BAR access when the kernel is locked down") to prevent DMA attacks when the kernel is locked down. Add the same check to Alpha's pci_mmap_resource().

Affected products

  • Linux Linux: from 5.4, before 5.10.261 (fixed in 5.10.261); from 5.11, before 5.15.212 (fixed in 5.15.212); from 5.16, before 6.1.178 (fixed in 6.1.178); from 6.2, before 6.6.145 (fixed in 6.6.145); from 6.7, before 6.12.97 (fixed in 6.12.97); from 6.13, before 6.18.40 (fixed in 6.18.40); …

Published 2026-09-04. Last modified 2026-09-04.