← Back to CVE search

CVE-2026-74443

Linux kernel

Description

In the Linux kernel, the following vulnerability has been resolved: drm/vmwgfx: bound DMA command body size against suffix pointer vmw_cmd_dma() locates the DMA suffix at (unsigned long) &cmd->body + header->size - sizeof(*suffix) without checking that header->size is large enough to contain both cmd->body and the suffix. An undersized header makes the suffix pointer underflow back into the previous command in the bounce buffer. The verifier later writes suffix->maximumOffset, clobbering verified fields of an already-relocated earlier command -- a TOCTOU on the device-visible command stream that lets one command rewrite another-s GMR id, surface id, or other authenticated fields. Reject the command if the body is too small for the suffix to fit.

CVSS 8.8EPSS 0.129%Risk 0.89
View source
Published
2026-08-15 13:17:48
Affected versions
unknown
Type
Kernel
Last modified
2026-08-19 17:21:01
Vector
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H