CVE-2026-16280
An integer overflow in the calculation of physical offsets for sparse PMRs can cause 32‑bit truncation when the PMR size exceeds 4 GB. This flaw can lead to incorrect GPU MMU mappings, allowing a non‑privileged user to access unintended physical memory.
No official fix yet. If none appears within 45 days of first tracking, this entry is removed automatically.
Who is affected
Systems that use sparse PMRs larger than 4 GB; no specific product versions are listed.
Real-world impact
A malicious user could read or corrupt memory that should be protected, potentially exposing sensitive data or destabilizing the system.
Why this severity
The CVSS score of 9.8 reflects that the flaw requires no authentication or user interaction, yet it can compromise confidentiality, integrity, and availability of the affected system.
What to do about it
No official fix or mitigation is documented in the sources yet. Monitor the vendor advisory and apply the patch as soon as it is released.
No fix documented in sources
Timeline
- Jul 24, 2026 · 7d agoPublishedDisclosed and added to the National Vulnerability Database.
- Jul 28, 2026 · 4d agoAdvisory updatedThe NVD record was last revised.