CVE-2026-23430: drm/vmwgfx: Don't overwrite KMS surface dirty tracker

Published Apr 3, 2026
·
Updated

In the Linux kernel, the following vulnerability has been resolved:

drm/vmwgfx: Don't overwrite KMS surface dirty tracker

We were overwriting the surface's dirty tracker here causing a memory leak.

Affected Software

11 affected components
Linux Linux kernel
Linux Linux kernel>=6.16.1<6.18.20
Linux Linux kernel>=6.19<6.19.10
Linux Linux kernel=6.16
Linux Linux kernel=7.0-rc1
Linux Linux kernel=7.0-rc2
Linux Linux kernel=7.0-rc3
Linux Linux kernel=7.0-rc4
Linux Linux kernel=7.0-rc5
Linux Linux kernel=7.0-rc6
Linux Linux kernel=7.0-rc7

Event History

Apr 3, 2026
CVE Published
via MITRE·03:15 PM
Data Sourced
via MITRE·03:15 PM
Description
Data Sourced
via NVD·04:16 PM
RemedyDescriptionSeverityWeaknessAffected Software

Frequently Asked Questions

1

Who is realistically exposed to this issue?

Systems running the Linux kernel with the drm/vmwgfx graphics driver are the relevant population. Exploitation requires local access and low privileges, according to the CVSS vector.

2

What impact can exploitation have?

The issue causes a memory leak by overwriting a KMS surface dirty tracker. The reported impact is availability loss; the CVSS vector indicates no confidentiality or integrity impact.

3

Does exploiting this require user interaction or special conditions?

No user interaction is required. The CVSS vector rates attack complexity as low, but the attack vector is local and requires low privileges.

4

What should be done to remediate the issue?

Update to a Linux kernel release containing the drm/vmwgfx fix referenced by the listed stable kernel commits. The provided information does not identify affected or fixed kernel version numbers.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203