What is CVE-2026-16280?
This vulnerability (CVE-2026-16280) causes integer overflow and 32-bit truncation of physical offsets for sparse PMRs larger than 4 GB, leading to incorrect GPU MMU mappings. It may allow a non-privileged user to access unintended physical memory, potentially resulting in memory corruption. Applying security patches on affected systems is critical.
Azərbaycanca: Bu boşluq (CVE-2026-16280) 32-bit qabaqcadan hesablanmış fiziki ünvanların kəsilməsi səbəbindən 4 GB-dan böyük PMR-lər üçün yanlış GPU MMU xəritələmələrinə yol açır. Bu, imtiyazsız istifadəçiyə qəsdən olmayan fiziki yaddaşa giriş imkanı verə bilər, bu da yaddaş korrupsiyası ilə nəticələnə bilər. Təsirə məruz qalan sistemlərdə təhlükəsizlik yamalarının tətbiqi vacibdir.
Related CVEs
link basis: same weakness class CWE-190
FAQ2
In which component does CVE-2026-16280 cause incorrect memory mappings?
This vulnerability leads to incorrect GPU MMU mappings for PMRs larger than 4 GB.
What risk can a non-privileged user face when exploiting CVE-2026-16280?
A non-privileged user may access unintended physical memory, potentially resulting in memory corruption.
See also6
This explainer is AI-written from source data — skopnix's own reporting on this CVE; CVSS scores, vendors and versions are never invented. See NVD for the official record.