CVE-2026-80867
alpha/PCI: Add security_locked_down() check to pci_mmap_resource()
Description
In the Linux kernel, the following vulnerability has been resolved: alpha/PCI: Add security_locked_down() check to pci_mmap_resource() Currently, Alpha's pci_mmap_resource() does not check security_locked_down(LOCKDOWN_PCI_ACCESS) before allowing userspace to mmap PCI BARs. The generic version has had this check since commit eb627e17727e ("PCI: Lock down BAR access when the kernel is locked down") to prevent DMA attacks when the kernel is locked down. Add the same check to Alpha's pci_mmap_resource().
INFO
Published Date :
Sept. 4, 2026, 5:16 p.m.
Last Modified :
Sept. 4, 2026, 5:16 p.m.
Remotely Exploit :
No
Source :
416baaa9-dc9f-4396-8d5f-8c081fb06d67
Affected Products
The following products are affected by CVE-2026-80867
vulnerability.
Even if cvefeed.io is aware of the exact versions of the
products
that
are
affected, the information is not represented in the table below.
No affected product recoded yet
Solution
- Apply the pci_mmap_resource() security check.
- Ensure kernel lockdown measures are enforced.
- Update the Linux kernel to the patched version.
References to Advisories, Solutions, and Tools
Here, you will find a curated list of external links that provide in-depth
information, practical solutions, and valuable tools related to
CVE-2026-80867.
CWE - Common Weakness Enumeration
While CVE identifies
specific instances of vulnerabilities, CWE categorizes the common flaws or
weaknesses that can lead to vulnerabilities. CVE-2026-80867 is
associated with the following CWEs:
Common Attack Pattern Enumeration and Classification (CAPEC)
Common Attack Pattern Enumeration and Classification
(CAPEC)
stores attack patterns, which are descriptions of the common attributes and
approaches employed by adversaries to exploit the CVE-2026-80867
weaknesses.
We scan GitHub repositories to detect new proof-of-concept exploits. Following list is a collection of public exploits and proof-of-concepts, which have been published on GitHub (sorted by the most recently updated).
Results are limited to the first 15 repositories due to potential performance issues.
The following list is the news that have been mention
CVE-2026-80867 vulnerability anywhere in the article.
The following table lists the changes that have been made to the
CVE-2026-80867 vulnerability over time.
Vulnerability history details can be useful for understanding the evolution of a vulnerability, and for identifying the most recent changes that may impact the vulnerability's severity, exploitability, or other characteristics.
-
New CVE Received by 416baaa9-dc9f-4396-8d5f-8c081fb06d67
Sep. 04, 2026
Action Type Old Value New Value Added Description In the Linux kernel, the following vulnerability has been resolved: alpha/PCI: Add security_locked_down() check to pci_mmap_resource() Currently, Alpha's pci_mmap_resource() does not check security_locked_down(LOCKDOWN_PCI_ACCESS) before allowing userspace to mmap PCI BARs. The generic version has had this check since commit eb627e17727e ("PCI: Lock down BAR access when the kernel is locked down") to prevent DMA attacks when the kernel is locked down. Add the same check to Alpha's pci_mmap_resource(). Added Affected New affected value received. <a href="https://github.com/CVEProject/cvelistV5/blob/main/cves/2026/80xxx/CVE-2026-80867.json">CVE-2026-80867</a> Added Reference https://git.kernel.org/stable/c/257b55dc3d18d7ef01f62a8ff7317871f7597e28 Added Reference https://git.kernel.org/stable/c/4de5ff924c0a8ef8166c1a68af9087826e1e8d61 Added Reference https://git.kernel.org/stable/c/6e368485a1ac19fbde0a8b6a332d4545ae72a8ac Added Reference https://git.kernel.org/stable/c/78a228f0aa0e9eba31955950c8a40a9945e2c8bb Added Reference https://git.kernel.org/stable/c/85f966b1120874fe530edec50d28373ceb06ebcd Added Reference https://git.kernel.org/stable/c/94defb18ac792fd16407d5a52ad0d3f5055c4b43 Added Reference https://git.kernel.org/stable/c/c3234efe21d4198945492cf7dba6859476f0f6ff Added Reference https://git.kernel.org/stable/c/ed2cd1fee0ed16a1c2dff49175e65c641eb8ae2b