Linux Kernel VMWGFX Driver Null Pointer Dereference Vulnerability on Hardware Version 10

Vulnerability

A vulnerability in the Linux kernel's VMWGFX graphics driver for Hardware version 10 has been fixed. This issue arose because Hardware version 10 lacks GB Surfaces, leading to the absence of a backing buffer for surface-backed framebuffers. Consequently, this situation caused a null pointer dereference, crashing the driver and resulting in a black screen.

Impact

Exploitation of this vulnerability caused a null pointer dereference, leading to a crash of the VMWGFX driver and a black screen.

Remediation

Users can download the patched version of the Linux kernel from the Linux kernel stable tree.

Added: Jan 25, 2026, 3:21 PM
Updated: Jan 25, 2026, 3:21 PM

Vulnerability Rating

Custom Algorithm
spread
9.0
impact
2.5
exploitability
3.5
remediation
7.7
relevance
2.4
threat
3.2
urgency
2.9
incentive
0.0

Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.