drm/vmwgfx: Validate the box size for the snooped cursor
3Vexday Risk Score
No sign of exploitation. No public exploitation artifact known so far.
ssvc Trackepss 0.1%
exploitation probability
0.1%top 95% of all CVEs
observed exploitation
nono source reports it
In the Linux kernel, the following vulnerability has been resolved:
drm/vmwgfx: Validate the box size for the snooped cursor
Invalid userspace dma surface copies could potentially overflow
the memcpy from the surface to the snooped image leading to crashes.
To fix it the dimensions of the copybox have to be validated
against the expected size of the snooped cursor.
Affected products
Linux · LinuxReferences
https://git.kernel.org/stable/c/439cbbc1519547f9a7b483f0de33b556ebfec901https://git.kernel.org/stable/c/4cf949c7fafe21e085a4ee386bb2dade9067316ehttps://git.kernel.org/stable/c/4d54d11b49860686331c58a00f733b16a93edfc4https://git.kernel.org/stable/c/50d177f90b63ea4138560e500d92be5e4c928186https://git.kernel.org/stable/c/622d527decaac0eb65512acada935a0fdc1d0202https://git.kernel.org/stable/c/6948e570f54f2044dd4da444b10471373a047eebhttps://git.kernel.org/stable/c/6b4e70a428b5a11f56db94047b68e144529fe512https://git.kernel.org/stable/c/94b283341f9f3f0ed56a360533766377a01540e0https://git.kernel.org/stable/c/ee8d31836cbe7c26e207bfa0a4a726f0a25cfcf6