drm/vmwgfx: Validate vmw_surface_metadata::array_size
Summary
| CVE | CVE-2026-68446 |
| State | PUBLISHED |
| Assigner | Linux |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2026-08-12 00:17:44 UTC |
| Updated | 2026-08-12 00:17:44 UTC |
| Description | In the Linux kernel, the following vulnerability has been resolved:
drm/vmwgfx: Validate vmw_surface_metadata::array_size
This field comes from userspace and should be validated against specific
limits depending on which Shader Model (SM) is available. |
Vendor Declared Affected Products
| Source | Vendor | Product | Version | Platforms |
|---|
| CNA |
Linux |
Linux |
affected 504901dbb0b565fcbe466b0c56f3131586df5afd 5ff94e1279176b539d451e3e754fdcbd1a8d520a git |
Not specified |
| CNA |
Linux |
Linux |
affected 504901dbb0b565fcbe466b0c56f3131586df5afd 71779fe8bf403a9b3e28dc59229fa556db32d35d git |
Not specified |
| CNA |
Linux |
Linux |
affected 504901dbb0b565fcbe466b0c56f3131586df5afd b1379f0c42b88cb60b9f3757eb5d1e73ad460ed8 git |
Not specified |
| CNA |
Linux |
Linux |
affected 504901dbb0b565fcbe466b0c56f3131586df5afd 6910ccaf41678f7761ba2e57d72b77d056320b4d git |
Not specified |
| CNA |
Linux |
Linux |
affected 504901dbb0b565fcbe466b0c56f3131586df5afd a4f55260f7f7d4dc4d0ee55063dfb0c457b77991 git |
Not specified |
| CNA |
Linux |
Linux |
affected 5.7 |
Not specified |
| CNA |
Linux |
Linux |
unaffected 5.7 semver |
Not specified |
| CNA |
Linux |
Linux |
unaffected 6.6.148 6.6.* semver |
Not specified |
| CNA |
Linux |
Linux |
unaffected 6.12.101 6.12.* semver |
Not specified |
| CNA |
Linux |
Linux |
unaffected 6.18.42 6.18.* semver |
Not specified |
| CNA |
Linux |
Linux |
unaffected 7.1.6 7.1.* semver |
Not specified |
| CNA |
Linux |
Linux |
unaffected 7.2-rc5 * original_commit_for_fix |
Not specified |
References
| Reference | Source | Link | Tags |
|---|
| git.kernel.org/stable/c/5ff94e1279176b539d451e3e754fdcbd1a8d520a |
416baaa9-dc9f-4396-8d5f-8c081fb06d67 |
git.kernel.org |
|
| git.kernel.org/stable/c/6910ccaf41678f7761ba2e57d72b77d056320b4d |
416baaa9-dc9f-4396-8d5f-8c081fb06d67 |
git.kernel.org |
|
| git.kernel.org/stable/c/71779fe8bf403a9b3e28dc59229fa556db32d35d |
416baaa9-dc9f-4396-8d5f-8c081fb06d67 |
git.kernel.org |
|
| git.kernel.org/stable/c/a4f55260f7f7d4dc4d0ee55063dfb0c457b77991 |
416baaa9-dc9f-4396-8d5f-8c081fb06d67 |
git.kernel.org |
|
| git.kernel.org/stable/c/b1379f0c42b88cb60b9f3757eb5d1e73ad460ed8 |
416baaa9-dc9f-4396-8d5f-8c081fb06d67 |
git.kernel.org |
|
| CVE Program record |
CVE.ORG |
www.cve.org |
canonical |
| NVD vulnerability detail |
NVD |
nvd.nist.gov |
canonical, analysis |
No vendor comments have been submitted for this CVE.
There are currently no legacy QID mappings associated with this CVE.