In the Linux kernel, the following vulnerability has been resolved:
drm/vmwgfx: Return the correct value in vmw_translate_ptr functions
Before the referenced fixes these functions used a lookup function that
returned a pointer. This was changed to another lookup function that
returned an error code with the pointer becoming an out parameter.
The error path when the lookup failed was not changed to reflect this
change and the code continued to return the PTR_ERR of the now
uninitialized pointer. This could cause the vmw_translate_ptr functions
to return success when they actually failed causing further uninitialized
and OOB accesses.
References
Configurations
Configuration 1 (hide)
|
History
23 Apr 2026, 21:09
| Type | Values Removed | Values Added |
|---|---|---|
| First Time |
Linux
Linux linux Kernel |
|
| CWE | CWE-908 | |
| CPE | cpe:2.3:o:linux:linux_kernel:7.0:rc1:*:*:*:*:*:* cpe:2.3:o:linux:linux_kernel:7.0:rc6:*:*:*:*:*:* cpe:2.3:o:linux:linux_kernel:7.0:rc7:*:*:*:*:*:* cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:* cpe:2.3:o:linux:linux_kernel:7.0:rc2:*:*:*:*:*:* cpe:2.3:o:linux:linux_kernel:6.2:-:*:*:*:*:*:* cpe:2.3:o:linux:linux_kernel:7.0:rc4:*:*:*:*:*:* cpe:2.3:o:linux:linux_kernel:7.0:rc3:*:*:*:*:*:* cpe:2.3:o:linux:linux_kernel:7.0:rc5:*:*:*:*:*:* |
|
| References | () https://git.kernel.org/stable/c/149f028772fa2879d9316b924ce948a6a0877e45 - Patch | |
| References | () https://git.kernel.org/stable/c/36cb28b6d303a81e6ed4536017090e85e0143e42 - Patch | |
| References | () https://git.kernel.org/stable/c/5023ca80f9589295cb60735016e39fc5cc714243 - Patch | |
| References | () https://git.kernel.org/stable/c/531f45589787799aa81b63e1e1f8e71db5d93dd1 - Patch | |
| References | () https://git.kernel.org/stable/c/7e55d0788b362c93660b80cc5603031bbbdefa98 - Patch | |
| References | () https://git.kernel.org/stable/c/ce3a5cf139787c186d5d54336107298cacaad2b9 - Patch |
02 Apr 2026, 15:16
| Type | Values Removed | Values Added |
|---|---|---|
| CVSS |
v2 : v3 : |
v2 : unknown
v3 : 7.8 |
| Summary |
|
25 Mar 2026, 11:16
| Type | Values Removed | Values Added |
|---|---|---|
| New CVE |
Information
Published : 2026-03-25 11:16
Updated : 2026-04-23 21:09
NVD link : CVE-2026-23317
Mitre link : CVE-2026-23317
CVE.ORG link : CVE-2026-23317
JSON object : View
Products Affected
linux
- linux_kernel
CWE
CWE-908
Use of Uninitialized Resource
