-

CVE-2026-74445

drm/vmwgfx: reject DX_BIND_QUERY without a DX context

In the Linux kernel, the following vulnerability has been resolved:

drm/vmwgfx: reject DX_BIND_QUERY without a DX context

vmw_cmd_dx_bind_query() unconditionally dereferences
sw_context->dx_ctx_node->ctx.  Userspace can trigger a NULL pointer
dereference from any render-node fd by submitting an execbuf with
dx_context_handle == SVGA3D_INVALID_ID and a SVGA_3D_CMD_DX_BIND_QUERY
opcode in the command stream: dx_ctx_node is left NULL and the kernel
oopses on the assignment.  The same NULL is then re-read in
vmw_resources_reserve() via vmw_context_get_dx_query_mob().

All sibling DX handlers fail-close on a missing dx_ctx_node using
VMW_GET_CTX_NODE().  Use the same pattern here, returning -EINVAL up
front before any relocation state is published.
Daten sind bereitgestellt durch das CVE Programm von einer CVE Numbering Authority (CNA) (Unstrukturiert).
HerstellerLinux
Produkt Linux
Default Statusunaffected
Version 9c079b8ce8bf8e0394149eb39c78b04285644bcc
Version < 7eae011829f94a76470ec76f016805f508437755
Status affected
Version 9c079b8ce8bf8e0394149eb39c78b04285644bcc
Version < 0634d50e8b398c25bd07c96b048e484d22688c26
Status affected
Version 9c079b8ce8bf8e0394149eb39c78b04285644bcc
Version < e479240a1e076ba1104236331abd62400bf1d495
Status affected
Version 9c079b8ce8bf8e0394149eb39c78b04285644bcc
Version < 6b1eb0b63cc153e1c0cb5ab8350950119be11947
Status affected
Version 9c079b8ce8bf8e0394149eb39c78b04285644bcc
Version < 55ec09c9ce10b1272802c7ab6c1be2ea0dbc68db
Status affected
HerstellerLinux
Produkt Linux
Default Statusaffected
Version 4.20
Status affected
Version 0
Version < 4.20
Status unaffected
Version <= 6.6.*
Version 6.6.151
Status unaffected
Version <= 6.12.*
Version 6.12.103
Status unaffected
Version <= 6.18.*
Version 6.18.44
Status unaffected
Version <= 7.1.*
Version 7.1.8
Status unaffected
Version <= *
Version 7.2
Status unaffected
VulnDex Vulnerability Enrichment
Diese Information steht angemeldeten Benutzern zur Verfügung. Login Login
Zu dieser CVE wurde keine Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 0.17% 0.065
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
Es wurden noch keine Informationen zu CWE veröffentlicht.
https://git.kernel.org/stable/c/7eae011829f94a76470ec76f016805f508437755
https://git.kernel.org/stable/c/0634d50e8b398c25bd07c96b048e484d22688c26
https://git.kernel.org/stable/c/e479240a1e076ba1104236331abd62400bf1d495
https://git.kernel.org/stable/c/6b1eb0b63cc153e1c0cb5ab8350950119be11947
https://git.kernel.org/stable/c/55ec09c9ce10b1272802c7ab6c1be2ea0dbc68db