SB20260325135 - NULL Pointer Dereference in Linux kernel drm vmwgfx driver
Published: March 25, 2026
Breakdown by Severity
- Low
- Medium
- High
- Critical
Description
This security bulletin contains information about 1 security vulnerability.
1) NULL Pointer Dereference (CVE-ID: CVE-2026-23317)
The vulnerability allows a local user to execute arbitrary code and escalate privileges.
The vulnerability exists due to improper error handling in the vmw_translate_ptr functions in the drm/vmwgfx subsystem when translating pointers. A local user can trigger a use of an uninitialized pointer to cause out-of-bounds memory accesses and execute arbitrary code.
Successful exploitation may lead to privilege escalation and system compromise.
Remediation
Install update from vendor's website.
References
- https://git.kernel.org/stable/c/149f028772fa2879d9316b924ce948a6a0877e45
- https://git.kernel.org/stable/c/36cb28b6d303a81e6ed4536017090e85e0143e42
- https://git.kernel.org/stable/c/5023ca80f9589295cb60735016e39fc5cc714243
- https://git.kernel.org/stable/c/531f45589787799aa81b63e1e1f8e71db5d93dd1
- https://git.kernel.org/stable/c/7e55d0788b362c93660b80cc5603031bbbdefa98
- https://git.kernel.org/stable/c/ce3a5cf139787c186d5d54336107298cacaad2b9