Database/Kernel, userspace & hypervisor
Intel Data Center GPU driver for VMware ESXi (buffer overflow): A buffer overflow in the Intel datacenter graphics
CVSS 9.3CVE-2026-20794Kernel, userspace & hypervisorcurated
Impact
A buffer overflow in the Intel datacenter graphics driver running in the ESXi device-driver ring lets a privileged local actor escalate and execute code. This is the GPU driver in the hypervisor - directly relevant to anyone running Intel Data Center GPU Flex/Max under ESXi.
Who can reach it
Local privileged access on the ESXi host.
What to do
Update the Intel Data Center Graphics Driver for ESXi to 2.0.2 or later. Driver VIB update plus host reboot, so it lands as part of a rolling host maintenance pass.
References
Related entries
- KVM arm64 vgic-its: double reference drop on the ITS translation cache frees an in-use interruptCVE-2026-46316 · Linux kernel KVM arm64 vgic-its (interrupt translation cache invalidation)Critical
- PREVAIL eBPF verifier: stale offset tracking lets out-of-bounds BPF programs pass verificationCVE-2026-53670 · PREVAIL eBPF verifier (EbpfTransformer::add offset tracking)Critical
- PREVAIL: writes through a context pointer are modelled as a no-op, so unsafe eBPF programs verify as safeCVE-2026-53671 · PREVAIL eBPF verifier (T_CTX store abstract transformer)Critical
- Linux kernel (arch/x86/kvm/svm): Page State Change requests from a confidential guest were validated against theCVE-2026-63938 · Linux kernel (arch/x86/kvm/svm)Critical
- Linux kernel (arch/x86/kvm/svm): KVM computed the usable size of the guest-provided GHCB scratch area wrongly, so aCVE-2026-63939 · Linux kernel (arch/x86/kvm/svm)Critical
- Linux kernel (arch/x86/kvm/svm): A confidential guest can hand KVM a port-I/O request with length or count zeroCVE-2026-63940 · Linux kernel (arch/x86/kvm/svm)Critical
This entry is curated: imported from vendor advisories with machine assistance, not yet individually verified. Confirm against your vendor's advisory before acting, and report anything wrong.