Linux Kernel KMS Surface Dirty Tracker Overwrite Vulnerability in VMWGFX Driver

Vulnerability

A memory leak vulnerability has been identified in the Linux kernel's VMWGFX graphics driver. The issue arises from an improper handling of the Kernel Mode Setting (KMS) surface dirty tracker, which is overwritten, leading to a memory leak. This vulnerability affects the stable versions of the Linux kernel.

Impact

Exploitation of this vulnerability causes a memory leak, which can lead to increased memory usage and potential degradation of system performance over time.

Reproduction

The vulnerability can be reproduced by using the VMWGFX graphics driver in a Linux environment. When KMS surfaces are managed, the driver's handling of the dirty tracker will incorrectly overwrite existing data, causing a memory leak. This can be observed by monitoring memory usage over time, which will show an increase due to the leaked resources.

Remediation

Users can upgrade to the latest version of the Linux kernel where this vulnerability has been addressed. Instructions for downloading the patched version are available on the official Linux kernel website.

Added: Apr 3, 2026, 5:16 PM
Updated: Apr 3, 2026, 5:16 PM

Vulnerability Rating

Custom Algorithm
spread
9.0
impact
2.5
exploitability
4.3
remediation
7.7
relevance
5.2
threat
4.8
urgency
2.9
incentive
0.0

Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.