Beschreibung
In the Linux kernel, the following vulnerability has been resolved: drm/vmwgfx: bound DMA command body size against suffix pointer vmw_cmd_dma() locates the DMA suffix at (unsigned long) &cmd->body + header->size - sizeof(*suffix) without checking that header->size is large enough to contain both cmd->body and the suffix. An undersized header makes the suffix pointer underflow back into the previous command in the bounce buffer. The verifier later writes suffix->maximumOffset, clobbering verified fields of an already-relocated earlier command -- a TOCTOU on the device-visible command stream that lets one command rewrite another-s GMR id, surface id, or other authenticated fields. Reject the command if the body is too small for the suffix to fit.
- Veröffentlicht
- 2026-08-15 13:17:48
- Betroffene Versionen
- unknown
- Typ
- Kernel
- Zuletzt geändert
- 2026-08-19 17:21:01
- Vektor
- CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H