GHSA-736r-87mh-h3grHighCVSS 7.8

In the Linux kernel, the following vulnerability has been resolved: drm/vmwgfx: fix...

Published
August 28, 2026
Last Modified
August 29, 2026

🔗 CVE IDs covered (1)

📋 Description

In the Linux kernel, the following vulnerability has been resolved:

drm/vmwgfx: fix guest_memory_dirty bitfield clobbered as size

Two sites in vmwgfx_resource.c assign boolean literals to res->guest_memory_size, which is an unsigned long allocation-size field; the intended target is the adjacent res->guest_memory_dirty bitfield. After the assignments the field holds 0 or 1 instead of the resource's MOB allocation size:

  • vmw_resource_release() writes 0 (false), and
  • vmw_resource_unbind_list() writes 1 (true).

Subsequent revalidation paths read guest_memory_size when computing the dirty page range (vmw_bo_dirty_transfer_to_res()) and the buffer allocation size (vmw_resource_buf_alloc()), producing zero-length walks or wrap-around ranges that read or write past the MOB bitmap. The dirty-tracking intent of the original code (mark the resource as dirtied since the last sync) is also lost, since guest_memory_dirty is never updated.

Rename both assignments to guest_memory_dirty.

🔗 References (7)