Linux kernel vmwgfx: undersized DRAW_PRIMITIVES header wraps the bound into an out-of-bounds read
Impact
vmw_cmd_draw() computed its declaration bound as (header->size - sizeof(cmd->body)) on a u32 taken straight from the user-supplied command stream. A header smaller than the body makes the unsigned subtraction wrap to nearly 4 GiB, so any numVertexDecls the caller supplies passes the check and the loop walks far past the end of the kernel command bounce buffer - an out-of-bounds read of kernel memory. In a VMware guest that is kernel memory disclosure, or a crash, driven by an unprivileged user with a render node. As with the sibling vmwgfx issue, the affected machines in a GPU estate are the ESXi-hosted management and utility VMs, not the accelerator nodes; guests that never load vmwgfx are unaffected.
Who can reach it
Unprivileged local user inside a VMware guest submitting a crafted command stream through an open /dev/dri render node. No remote path.
What to do
Update the guest kernel to a stable release with the header-size check and reboot the guest. Blacklisting vmwgfx on headless server VMs closes it without waiting for a kernel roll. Same window as CVE-2026-68446 - take both fixes together.
References
Related entries
- Linux kernel amdgpu display core (DC/DM) (drm/amd/display): An out-of-bounds access in the amdgpu display core (DC/DM)CVE-2026-74449 · Linux kernel amdgpu display core (DC/DM) (drm/amd/display)High
- Linux kernel amdgpu power management (SMU/powerplay) (drm/amd/pm): A use-after-free in the amdgpu power managementCVE-2026-74450 · Linux kernel amdgpu power management (SMU/powerplay) (drm/amd/pm)High
- Linux kernel drm_gem_shmem: PMD huge-page fault can map past the VMA end and trip VM_BUG_ONCVE-2026-80582 · Linux kernel DRM GEM shmem helper (drm_gem_shmem ->huge_fault PMD path)High
- Linux kernel drm/xe: userptr inject path takes notifier_lock for read, tripping a GPU SVM lock assertionCVE-2026-80606 · Linux kernel drm/xe userptr (notifier_lock held for read on the invalidation-inject path)High
- Linux kernel drm/vmwgfx: unvalidated offsets and strides overrun imported dma-buf maps in BO copyCVE-2026-80700 · Linux kernel drm/vmwgfx (vmw_external_bo_copy stride and offset validation)High
- Linux kernel drm/vmwgfx: boolean written to guest_memory_size drives out-of-bounds MOB dirty walksCVE-2026-80702 · Linux kernel drm/vmwgfx (vmw_resource guest_memory_size clobbered by boolean assignment)High
This entry is curated: imported from vendor advisories with machine assistance, not yet individually verified. Confirm against your vendor's advisory before acting, and report anything wrong.