CVE-2026-68446
In the Linux kernel, the following vulnerability has been resolved: drm/vmwgfx: Validate vmw_surface_metadata::array_size This field comes from userspace and should be validated against specific limits depending on which Shader Model (SM) is available.
Does this matter?
High impact if exploited, but EPSS currently rates exploitation as unlikely (0.12%). Schedule it in the normal patch cycle and watch for a rise in EPSS or a public exploit.
Description
In the Linux kernel, the following vulnerability has been resolved: drm/vmwgfx: Validate vmw_surface_metadata::array_size This field comes from userspace and should be validated against specific limits depending on which Shader Model (SM) is available.
- CVSS 3.1
- 7.8 HIGHCVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
- EPSS
- 0.12% probability · 2th percentile
- CISA KEV
- Not listed
- Source
- 416baaa9-dc9f-4396-8d5f-8c081fb06d67
References
- https://git.kernel.org/stable/c/0403cec2aff8037bc246cf9a0831eb169ddcd9df
- https://git.kernel.org/stable/c/5ff94e1279176b539d451e3e754fdcbd1a8d520a
- https://git.kernel.org/stable/c/6910ccaf41678f7761ba2e57d72b77d056320b4d
- https://git.kernel.org/stable/c/71779fe8bf403a9b3e28dc59229fa556db32d35d
- https://git.kernel.org/stable/c/a4f55260f7f7d4dc4d0ee55063dfb0c457b77991
- https://git.kernel.org/stable/c/aded8463466ede7a7fbd1bbf821756c67c83e89b
- https://git.kernel.org/stable/c/b1379f0c42b88cb60b9f3757eb5d1e73ad460ed8
- https://git.kernel.org/stable/c/e949adf2d42678fb391a41db277e2fcb12090566
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.