← Retour à la recherche de CVE

CVE-2026-74443

Linux kernel

Description

In the Linux kernel, the following vulnerability has been resolved: drm/vmwgfx: bound DMA command body size against suffix pointer vmw_cmd_dma() locates the DMA suffix at (unsigned long) &cmd->body + header->size - sizeof(*suffix) without checking that header->size is large enough to contain both cmd->body and the suffix. An undersized header makes the suffix pointer underflow back into the previous command in the bounce buffer. The verifier later writes suffix->maximumOffset, clobbering verified fields of an already-relocated earlier command -- a TOCTOU on the device-visible command stream that lets one command rewrite another-s GMR id, surface id, or other authenticated fields. Reject the command if the body is too small for the suffix to fit.

CVSS 8.8EPSS 0.129%Risque 0.89
Voir la source
Publication
2026-08-15 13:17:48
Versions concernées
unknown
Type
Noyau
Dernière modification
2026-08-19 17:21:01
Vecteur
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H