Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2026-23008

Опубликовано: 25 янв. 2026
Источник: redhat
CVSS3: 5.5

Описание

In the Linux kernel, the following vulnerability has been resolved: drm/vmwgfx: Fix KMS with 3D on HW version 10 HW version 10 does not have GB Surfaces so there is no backing buffer for surface backed FBs. This would result in a nullptr dereference and crash the driver causing a black screen.

A NULL pointer dereference vulnerability was found in the Linux kernel's VMware graphics (vmwgfx) driver. On VMware hardware version 10, which lacks GB Surfaces support, attempting to use 3D acceleration with KMS (Kernel Mode Setting) causes the driver to dereference a NULL backing buffer pointer for surface-backed framebuffers. This results in a kernel crash and black screen.

Отчет

This vulnerability specifically affects VMware virtual machines running hardware version 10 with 3D acceleration enabled. The crash occurs when the DRM subsystem attempts to access framebuffer surfaces that don't have backing storage on this hardware version. Newer VMware hardware versions are not affected as they support GB Surfaces.

Меры по смягчению последствий

To mitigate this issue, disable 3D acceleration in VMware virtual machine settings when using hardware version 10, or upgrade to a newer VMware hardware version that supports GB Surfaces.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Red Hat Enterprise Linux 10kernelAffected
Red Hat Enterprise Linux 6kernelOut of support scope
Red Hat Enterprise Linux 7kernelNot affected
Red Hat Enterprise Linux 7kernel-rtNot affected
Red Hat Enterprise Linux 8kernelNot affected
Red Hat Enterprise Linux 8kernel-rtNot affected
Red Hat Enterprise Linux 9kernelAffected
Red Hat Enterprise Linux 9kernel-rtAffected

Показывать по

Дополнительная информация

Статус:

Low
Дефект:
CWE-824
https://bugzilla.redhat.com/show_bug.cgi?id=2432675kernel: drm/vmwgfx: Fix KMS with 3D on HW version 10

5.5 Medium

CVSS3

Связанные уязвимости

ubuntu
2 месяца назад

In the Linux kernel, the following vulnerability has been resolved: drm/vmwgfx: Fix KMS with 3D on HW version 10 HW version 10 does not have GB Surfaces so there is no backing buffer for surface backed FBs. This would result in a nullptr dereference and crash the driver causing a black screen.

nvd
2 месяца назад

In the Linux kernel, the following vulnerability has been resolved: drm/vmwgfx: Fix KMS with 3D on HW version 10 HW version 10 does not have GB Surfaces so there is no backing buffer for surface backed FBs. This would result in a nullptr dereference and crash the driver causing a black screen.

debian
2 месяца назад

In the Linux kernel, the following vulnerability has been resolved: d ...

CVSS3: 5.5
github
2 месяца назад

In the Linux kernel, the following vulnerability has been resolved: drm/vmwgfx: Fix KMS with 3D on HW version 10 HW version 10 does not have GB Surfaces so there is no backing buffer for surface backed FBs. This would result in a nullptr dereference and crash the driver causing a black screen.

CVSS3: 5.5
fstec
3 месяца назад

Уязвимость функции vmw_kms_fb_create() модуля drivers/gpu/drm/vmwgfx/vmwgfx_kms.c драйвера инфраструктуры прямого рендеринга (DRI) ядра операционной системы Linux, позволяющая нарушителю вызвать отказ в обслуживании

5.5 Medium

CVSS3