Database/Kernel, userspace & hypervisor
Linux kernel (drivers/gpu/drm/vmwgfx): A tenant that asks for a fence event on its DRM fd and then reads the fd back
Impact
A tenant that asks for a fence event on its DRM fd and then reads the fd back gets more bytes than the event actually contains, so adjacent kernel heap memory is copied into its buffer. That is a straight kernel-memory read primitive from an unprivileged process - enough to defeat KASLR and to harvest residual data left by other work on the box.
Who can reach it
An unprivileged process inside a VMware-hosted guest holding /dev/dri/card* or /dev/dri/renderD*: issue the vmwgfx fence-event ioctl, then read() the DRM fd. No capabilities needed. Only applies where vmwgfx is the GPU driver (ESXi/Workstation guests), so the exposure is tenant VMs, not bare-metal GPU nodes.
What to do
Boot a kernel carrying the fix (the record lists no fixed_in - take the stable backport from your distro tree, commits below). Interim: do not expose /dev/dri to untrusted processes inside vmwgfx guests.
References
Related entries
- Linux kernel (drivers/gpu/drm/vmwgfx): When the copy of the fence reply back to userspace fails, the driver installs aCVE-2022-48771 · Linux kernel (drivers/gpu/drm/vmwgfx)High
- Linux kernel (drivers/gpu/drm/vmwgfx): User-resource lookup during command submission used a broken RCU fast path, soCVE-2022-48887 · Linux kernel (drivers/gpu/drm/vmwgfx)High
- Linux kernel (drivers/gpu/drm/vmwgfx): The dimensions of a DMA surface-copy box submitted in the command stream wereCVE-2022-50440 · Linux kernel (drivers/gpu/drm/vmwgfx)High
- Linux kernel (drivers/gpu/drm/vmwgfx): A guest process can get a node left in the vmwgfx validation hash table afterCVE-2025-40111 · Linux kernel (drivers/gpu/drm/vmwgfx)High
- Linux kernel (drivers/gpu/drm/vmwgfx): The vmwgfx command-buffer parser trusted a size field taken straight from theCVE-2025-40277 · Linux kernel (drivers/gpu/drm/vmwgfx)High
- Linux kernel (drivers/iommu/iommufd): A tenant supplies an IOVA and user pointer whose alignment math overflows, soCVE-2024-47719 · Linux kernel (drivers/iommu/iommufd)High
This entry is curated: imported from vendor advisories with machine assistance, not yet individually verified. Confirm against your vendor's advisory before acting, and report anything wrong.