drm/vmwgfx: reject DX_BIND_QUERY without a DX context
Summary
| CVE | CVE-2026-74445 |
| State | PUBLISHED |
| Assigner | Linux |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2026-08-15 13:17:49 UTC |
| Updated | 2026-08-15 13:17:49 UTC |
| Description | In the Linux kernel, the following vulnerability has been resolved:
drm/vmwgfx: reject DX_BIND_QUERY without a DX context
vmw_cmd_dx_bind_query() unconditionally dereferences
sw_context->dx_ctx_node->ctx. Userspace can trigger a NULL pointer
dereference from any render-node fd by submitting an execbuf with
dx_context_handle == SVGA3D_INVALID_ID and a SVGA_3D_CMD_DX_BIND_QUERY
opcode in the command stream: dx_ctx_node is left NULL and the kernel
oopses on the assignment. The same NULL is then re-read in
vmw_resources_reserve() via vmw_context_get_dx_query_mob().
All sibling DX handlers fail-close on a missing dx_ctx_node using
VMW_GET_CTX_NODE(). Use the same pattern here, returning -EINVAL up
front before any relocation state is published. |
Vendor Declared Affected Products
| Source | Vendor | Product | Version | Platforms |
|---|
| CNA |
Linux |
Linux |
affected 9c079b8ce8bf8e0394149eb39c78b04285644bcc 7eae011829f94a76470ec76f016805f508437755 git |
Not specified |
| CNA |
Linux |
Linux |
affected 9c079b8ce8bf8e0394149eb39c78b04285644bcc 0634d50e8b398c25bd07c96b048e484d22688c26 git |
Not specified |
| CNA |
Linux |
Linux |
affected 9c079b8ce8bf8e0394149eb39c78b04285644bcc e479240a1e076ba1104236331abd62400bf1d495 git |
Not specified |
| CNA |
Linux |
Linux |
affected 9c079b8ce8bf8e0394149eb39c78b04285644bcc 6b1eb0b63cc153e1c0cb5ab8350950119be11947 git |
Not specified |
| CNA |
Linux |
Linux |
affected 9c079b8ce8bf8e0394149eb39c78b04285644bcc 55ec09c9ce10b1272802c7ab6c1be2ea0dbc68db git |
Not specified |
| CNA |
Linux |
Linux |
affected 4.20 |
Not specified |
| CNA |
Linux |
Linux |
unaffected 4.20 semver |
Not specified |
| CNA |
Linux |
Linux |
unaffected 6.6.151 6.6.* semver |
Not specified |
| CNA |
Linux |
Linux |
unaffected 6.12.103 6.12.* semver |
Not specified |
| CNA |
Linux |
Linux |
unaffected 6.18.44 6.18.* semver |
Not specified |
| CNA |
Linux |
Linux |
unaffected 7.1.8 7.1.* semver |
Not specified |
| CNA |
Linux |
Linux |
unaffected 7.2-rc6 * original_commit_for_fix |
Not specified |
References
| Reference | Source | Link | Tags |
|---|
| git.kernel.org/stable/c/e479240a1e076ba1104236331abd62400bf1d495 |
416baaa9-dc9f-4396-8d5f-8c081fb06d67 |
git.kernel.org |
|
| git.kernel.org/stable/c/55ec09c9ce10b1272802c7ab6c1be2ea0dbc68db |
416baaa9-dc9f-4396-8d5f-8c081fb06d67 |
git.kernel.org |
|
| git.kernel.org/stable/c/0634d50e8b398c25bd07c96b048e484d22688c26 |
416baaa9-dc9f-4396-8d5f-8c081fb06d67 |
git.kernel.org |
|
| git.kernel.org/stable/c/7eae011829f94a76470ec76f016805f508437755 |
416baaa9-dc9f-4396-8d5f-8c081fb06d67 |
git.kernel.org |
|
| git.kernel.org/stable/c/6b1eb0b63cc153e1c0cb5ab8350950119be11947 |
416baaa9-dc9f-4396-8d5f-8c081fb06d67 |
git.kernel.org |
|
| CVE Program record |
CVE.ORG |
www.cve.org |
canonical |
| NVD vulnerability detail |
NVD |
nvd.nist.gov |
canonical, analysis |
No vendor comments have been submitted for this CVE.
There are currently no legacy QID mappings associated with this CVE.