Database/Kernel, userspace & hypervisor
Linux kernel (drivers/gpu/drm/vmwgfx): A guest process can get a node left in the vmwgfx validation hash table after
Impact
A guest process can get a node left in the vmwgfx validation hash table after its backing resource has already been destroyed, so the next command submission dereferences freed memory. Use-after-free inside the execbuf validation path is directly weaponisable for guest kernel privilege escalation, and it lives in the code that every 3D command submission goes through.
Who can reach it
Reachable by any process inside a VMware guest that holds /dev/dri/renderD* or /dev/dri/card* - the bug is in vmw_execbuf_process's validation bookkeeping, so it is on the ordinary command-submission path. Relevant wherever tenant workloads run as VMware guests with the paravirtual vmwgfx GPU exposed; not applicable to bare-metal GPU nodes.
What to do
Update guest kernels to a build carrying the fix commits below. Interim: drop /dev/dri device nodes from untrusted guest containers, or configure the VM without the vmwgfx 3D device so the render node is not present.
References
Related entries
- Linux kernel (drivers/gpu/drm/vmwgfx): The vmwgfx command-buffer parser trusted a size field taken straight from theCVE-2025-40277 · Linux kernel (drivers/gpu/drm/vmwgfx)High
- Linux kernel (drivers/gpu/drm/vmwgfx): A tenant that asks for a fence event on its DRM fd and then reads the fd backCVE-2024-36960 · Linux kernel (drivers/gpu/drm/vmwgfx)High
- Linux kernel (drivers/gpu/drm/vmwgfx): When the copy of the fence reply back to userspace fails, the driver installs aCVE-2022-48771 · Linux kernel (drivers/gpu/drm/vmwgfx)High
- Linux kernel (drivers/gpu/drm/vmwgfx): User-resource lookup during command submission used a broken RCU fast path, soCVE-2022-48887 · Linux kernel (drivers/gpu/drm/vmwgfx)High
- Linux kernel (drivers/gpu/drm/vmwgfx): The dimensions of a DMA surface-copy box submitted in the command stream wereCVE-2022-50440 · Linux kernel (drivers/gpu/drm/vmwgfx)High
- Linux kernel BPF: tailcalls ignore expected_attach_type, yielding NULL deref and bypassed context checksCVE-2025-40123 · Linux kernel BPF tailcall map compatibility (__bpf_prog_map_compatible)High
This entry is curated: imported from vendor advisories with machine assistance, not yet individually verified. Confirm against your vendor's advisory before acting, and report anything wrong.