SB2026081283 - Improper input validation in Linux kernel drm vmwgfx driver
Published: August 12, 2026
Breakdown by Severity
- Low
- Medium
- High
- Critical
Description
This security bulletin contains information about 1 vulnerability.
1) Improper input validation (CVE-ID: CVE-2026-68446)
CWE-ID: CWE-20 - Improper input validation
CVSSv4: 6.8 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N]
The vulnerability allows a local user to cause a denial of service.
The vulnerability exists due to improper input validation in vmw_gb_surface_define_internal when handling a userspace surface creation request with a crafted array_size value. A local user can submit a specially crafted request to cause a denial of service.
The array_size limit depends on which Shader Model is available.
Remediation
Install update from vendor's website.
References
- https://git.kernel.org/stable/c/5ff94e1279176b539d451e3e754fdcbd1a8d520a
- https://git.kernel.org/stable/c/6910ccaf41678f7761ba2e57d72b77d056320b4d
- https://git.kernel.org/stable/c/71779fe8bf403a9b3e28dc59229fa556db32d35d
- https://git.kernel.org/stable/c/a4f55260f7f7d4dc4d0ee55063dfb0c457b77991
- https://git.kernel.org/stable/c/b1379f0c42b88cb60b9f3757eb5d1e73ad460ed8