Linux Kernel VMWGFX DRM Subsystem Out-of-Bounds Access Vulnerability

Vulnerability

A vulnerability in the Linux kernel's VMWGFX Direct Rendering Manager (DRM) subsystem can lead to out-of-bounds accesses. This issue arises in the 'vmw_translate_ptr' functions, which improperly handle pointer translations. The vulnerability exists in several Linux kernel versions within the stable group.

Impact

The vulnerability can cause out-of-bounds accesses, potentially leading to memory corruption or unauthorized memory access.

Reproduction

The vulnerability can be reproduced by using the VMWGFX DRM subsystem in the Linux kernel. The 'vmw_translate_ptr' functions will return success even when they fail, due to an error in how pointer lookups are handled. This flaw can be triggered by scenarios that require translating memory object buffer pointers or guest pointers, which are common in graphics operations.

Remediation

Users can upgrade to the latest version of the Linux kernel where this vulnerability has been fixed. The specific commit that addresses this issue is '5023ca80f9589295cb60735016e39fc5cc714243', which is available in the Linux kernel Git repository.

Added: Mar 25, 2026, 12:50 PM
Updated: Mar 25, 2026, 12:50 PM

Vulnerability Rating

Custom Algorithm
spread
9.0
impact
3.8
exploitability
3.9
remediation
7.7
relevance
4.7
threat
4.8
urgency
2.9
incentive
0.0

Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.