CVE-2026-80883 PUBLISHED

drm/tegra: gr2d/gr3d: Initialize address register map before HOST1X client is registered

Assigner: Linux
Reserved: 26.08.2026 Published: 04.09.2026 Updated: 04.09.2026

In the Linux kernel, the following vulnerability has been resolved:

drm/tegra: gr2d/gr3d: Initialize address register map before HOST1X client is registered

The host1x_client_register() function is called just prior to register map initialization loop, making the device available to userspace. This may result in userspace attempting to submits a job before the register map is initialized. Address this by moving register initialization before host1x client registration.

Product Status

Vendor Linux
Product Linux
Versions Default: unaffected
  • affected from 1da177e4c3f41524e886b7f1b8a0c1fc7321cac2 to 6e22d5ad61cfa38aa53fab86a530113aff6a3619 (excl.)
  • affected from 1da177e4c3f41524e886b7f1b8a0c1fc7321cac2 to 5db37fd7710e74bc4df48bddab8f571d0bfc6769 (excl.)
  • affected from 1da177e4c3f41524e886b7f1b8a0c1fc7321cac2 to 40a2a91da02c434938f0ba53877984820800b5f0 (excl.)
  • affected from 1da177e4c3f41524e886b7f1b8a0c1fc7321cac2 to 3055292b8eed69553b389a609197a241df47e68e (excl.)
  • affected from 1da177e4c3f41524e886b7f1b8a0c1fc7321cac2 to c4ef5ba1131346159e31f4ef858525cf377380a6 (excl.)
  • affected from 0 to 6.6.145 (excl.)
  • affected from 0 to 6.12.97 (excl.)
  • affected from 0 to 6.18.40 (excl.)
  • affected from 0 to 7.1.5 (excl.)
Vendor Linux
Product Linux
Versions Default: affected
  • unaffected from 6.6.145 to 6.6.* (incl.)
  • unaffected from 6.12.97 to 6.12.* (incl.)
  • unaffected from 6.18.40 to 6.18.* (incl.)
  • unaffected from 7.1.5 to 7.1.* (incl.)
  • unaffected from 7.2 to * (incl.)

References