cbcvebase.
CVE-2026-23317
published 2026-03-25

CVE-2026-23317: In the Linux kernel, the following vulnerability has been resolved: drm/vmwgfx: Return the correct value in vmw_translate_ptr functions Before the referenced…

PriorityP338high7.8CVSS 3.1
AVLACLPRLUINSUCHIHAH
EPSS
0.13%
3.0th percentile
In the Linux kernel, the following vulnerability has been resolved: drm/vmwgfx: Return the correct value in vmw_translate_ptr functions Before the referenced fixes these functions used a lookup function that returned a pointer. This was changed to another lookup function that returned an error code with the pointer becoming an out parameter. The error path when the lookup failed was not changed to reflect this change and the code continued to return the PTR_ERR of the now uninitialized pointer. This could cause the vmw_translate_ptr functions to return success when they actually failed causing further uninitialized and OOB accesses.

Affected

46 ranges· showing 25
VendorProductVersion rangeFixed in
debianlinux< linux 6.19.8-1 (forky)linux 6.19.8-1 (forky)
linuxlinux
linuxlinux>= 6.1.7 < 6.1.1676.1.167
linuxlinux>= 7ac9578e45b20e3f3c0c8eb71f5417a499a7226a < ce3a5cf139787c186d5d54336107298cacaad2b9ce3a5cf139787c186d5d54336107298cacaad2b9
linuxlinux>= a309c7194e8a2f8bd4539b9449917913f6c2cd50 < 7e55d0788b362c93660b80cc5603031bbbdefa987e55d0788b362c93660b80cc5603031bbbdefa98
linuxlinux>= a309c7194e8a2f8bd4539b9449917913f6c2cd50 < 36cb28b6d303a81e6ed4536017090e85e0143e4236cb28b6d303a81e6ed4536017090e85e0143e42
linuxlinux>= a309c7194e8a2f8bd4539b9449917913f6c2cd50 < 531f45589787799aa81b63e1e1f8e71db5d93dd1531f45589787799aa81b63e1e1f8e71db5d93dd1
linuxlinux>= a309c7194e8a2f8bd4539b9449917913f6c2cd50 < 149f028772fa2879d9316b924ce948a6a0877e45149f028772fa2879d9316b924ce948a6a0877e45
linuxlinux>= a309c7194e8a2f8bd4539b9449917913f6c2cd50 < 5023ca80f9589295cb60735016e39fc5cc7142435023ca80f9589295cb60735016e39fc5cc714243
linuxlinux_kernel< 6.12.776.12.77
linuxlinux_kernel
linuxlinux_kernel
linuxlinux_kernel>= 0 < 6.19.8-16.19.8-1
linuxlinux_kernel>= 0 < 6.1.1676.1.167
linuxlinux_kernel>= 6.1.7 < 6.1.1676.1.167
linuxlinux_kernel>= 6.13 < 6.18.176.18.17
linuxlinux_kernel>= 6.13.0 < 6.19.76.19.7
linuxlinux_kernel>= 6.19 < 6.19.76.19.7
linuxlinux_kernel>= 6.2.0 < 6.6.1306.6.130
linuxlinux_kernel>= 6.2.1 < 6.6.1306.6.130
linuxlinux_kernel>= 6.7 < 6.12.776.12.77
linuxlinux_kernel>= 6.7.0 < 6.18.176.18.17
msrcazl3_kernel_6.6.126.1-1_on_azure_linux_3.0
ubuntulinux
ubuntulinux-aws

CVSS provenance

nvdv3.17.8HIGHCVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
osv7.8HIGH
vendor_debian7.8HIGH
vendor_redhat7.8HIGH
vendor_msrc5.5MEDIUM
vendor_ubuntu2.0LOW
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.