CVE-2026-80703

high

Description

In the Linux kernel, the following vulnerability has been resolved: drm/amdkfd: Fix missing authorization check in KFD_IOC_DBG_TRAP_DISABLE Prevent unauthorized termination of active GPU debug sessions. Previously, users with /dev/kfd access could terminate another process's debug session without proper ownership or ptrace authorization. (cherry picked from commit 4db4c5ffd5585b72622ecf6ffedf2da258ee23f5)

References

https://git.kernel.org/stable/c/ce813614f63b020a826071276a92f2cfae7cba79

https://git.kernel.org/stable/c/b8c05061997408bf81759f2dd31cd5f66771d15f

https://git.kernel.org/stable/c/9e52212aff8ed1fd9087728f61243ce3efd9d0ac

https://git.kernel.org/stable/c/99b2fe4f19e3be0a8d0a0b5ea98d855970889653

https://git.kernel.org/stable/c/4070909ac042f44654aac72f7986ea550c96f591

https://euvd.enisa.europa.eu/vulnerability/EUVD-2026-67438

Details

Source: Mitre, NVD

Published: 2026-08-28

Updated: 2026-08-30

Risk Information

CVSS v2

Base Score: 10

Vector: CVSS2#AV:N/AC:L/Au:N/C:C/I:C/A:C

Severity: Critical

CVSS v3

Base Score: 8.4

Vector: CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

Severity: High

EPSS

EPSS: 0.00209