CVE-2026-80883
Linux Debian vulnerability analysis and mitigation

Overview

CVE-2026-80883 is a use-before-initialization vulnerability in the Linux kernel's drm/tegra graphics driver (gr2d/gr3d subsystem). The flaw arises because host1x_client_register() is called before the address register map initialization loop completes, making the Tegra graphics device available to userspace prematurely. It affects Linux kernel versions across multiple stable branches: before 6.6.145, before 6.12.97, before 6.18.40, and before 7.1.5. The vulnerability was published on September 4, 2026, with patches available the same day. The CVSS base score is listed as 0.0 (no official severity rating assigned at time of publication), though Feedly estimates it as Medium severity (GitHub Advisory, Feedly).

Technical details

The root cause is a race condition / use-before-initialization (CWE-908) in the drm/tegra driver's initialization sequence. Specifically, host1x_client_register() exposes the device to userspace before the address register map has been fully populated in the subsequent initialization loop. A local user with access to the Tegra graphics device node can submit a job via the HOST1X interface during this narrow initialization window, causing the kernel driver to operate on an uninitialized register map. The fix reorders initialization so that the register map is fully set up before host1x_client_register() is called, eliminating the race (GitHub Advisory, Kernel Patch).

Impact

Successful exploitation could lead to memory corruption or kernel-level code execution within the context of the Tegra graphics driver, as uninitialized memory is accessed during job processing. The impact is limited to systems running Linux on NVIDIA Tegra hardware (e.g., embedded systems, Jetson platforms) where a local user has access to the graphics device. Confidentiality, integrity, and availability of the kernel graphics subsystem are all potentially affected, though lateral movement beyond the local system is unlikely given the local-only attack vector (Feedly).

Exploitability

There is no public proof-of-concept exploit and no evidence of in-the-wild exploitation as of the publication date. The attack requires local access to a Tegra graphics device, significantly limiting the attack surface. The EPSS score is 0.0, and the vulnerability is not listed in the CISA Known Exploited Vulnerabilities catalog. No threat actor attribution has been reported (GitHub Advisory, Feedly).

Mitigation and workarounds

Update the Linux kernel to a patched version: 6.6.145 or later (6.6.x branch), 6.12.97 or later (6.12.x branch), 6.18.40 or later (6.18.x branch), 7.1.5 or later (7.1.x branch), or 7.2 and above. The fix is available via multiple stable-tree commits (e.g., 6e22d5ad61cf, 5db37fd7710e, 40a2a91da02c, 3055292b8eed, c4ef5ba11313). No configuration-based workaround is documented; upgrading to a patched kernel is the recommended remediation (GitHub Advisory, Kernel Patch).

Additional resources


SourceThis report was generated using AI

Related Linux Debian vulnerabilities:

CVE ID

Severity

Score

Technologies

Component name

CISA KEV exploit

Has fix

Published date

CVE-2026-80886NONEN/A
  • Linux Debian logoLinux Debian
  • linux
NoYesSep 04, 2026
CVE-2026-80885NONEN/A
  • Linux Debian logoLinux Debian
  • linux
NoYesSep 04, 2026
CVE-2026-80884NONEN/A
  • Linux Debian logoLinux Debian
  • linux
NoYesSep 04, 2026
CVE-2026-80883NONEN/A
  • Linux Debian logoLinux Debian
  • linux
NoYesSep 04, 2026
CVE-2026-80882NONEN/A
  • Linux Debian logoLinux Debian
  • linux
NoYesSep 04, 2026

Free Vulnerability Assessment

Benchmark your Cloud Security Posture

Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.

Request assessment

Get a personalized demo

Ready to see Wiz in action?

"Best User Experience I have ever seen, provides full visibility to cloud workloads."
David EstlickCISO
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
Adam FletcherChief Security Officer
"We know that if Wiz identifies something as critical, it actually is."
Greg PoniatowskiHead of Threat and Vulnerability Management