{"apiVersion":"1.0","identifier":"CVE-2026-74443","description":"In the Linux kernel, the following vulnerability has been resolved: drm/vmwgfx: bound DMA command body size against suffix pointer vmw_cmd_dma() locates the DMA suffix at (unsigned long) &cmd->body + header->size - sizeof(*suffix) without checking that header->size is large enough to contain both cmd->body and the suffix. An undersized header makes the suffix pointer underflow back into the previous command in the bounce buffer. The verifier later writes suffix->maximumOffset, clobbering verified fields of an already-relocated earlier command -- a TOCTOU on the device-visible command stream that lets one command rewrite another-s GMR id, surface id, or other authenticated fields. Reject the command if the body is too small for the suffix to fit.","publishedAt":"2026-08-15T13:17:48","lastModifiedAt":"2026-08-19T17:21:01","sourceUrl":"https://nvd.nist.gov/vuln/detail/CVE-2026-74443","cvssScore":8.8,"cvssVector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H","epssProbability":0.00129,"riskScore":0.89,"affectedProduct":"Linux kernel","affectedVersions":"unknown","vulnerabilityType":"Kernel","operatingSystems":[],"links":{"self":"https://www.redsauce.net/api/cves/CVE-2026-74443","webPages":{"es":"https://www.redsauce.net/es/cves/CVE-2026-74443","en":"https://www.redsauce.net/en/cves/CVE-2026-74443","fr":"https://www.redsauce.net/fr/cves/CVE-2026-74443","pt":"https://www.redsauce.net/pt/cves/CVE-2026-74443","de":"https://www.redsauce.net/de/cves/CVE-2026-74443","sk":"https://www.redsauce.net/sk/cves/CVE-2026-74443","el":"https://www.redsauce.net/el/cves/CVE-2026-74443"},"source":"https://nvd.nist.gov/vuln/detail/CVE-2026-74443"}}