Impact
The vulnerability involves the vmw_surface_metadata::array_size field that originates in userspace and is used by the Linux kernel's DRM vmwgfx driver. Without proper validation against limits tied to the available Shader Model, an attacker could supply an oversized or otherwise malformed value that may lead to memory corruption or a kernel panic, potentially granting elevated privileges or disrupting system availability.
Affected Systems
All Linux kernel versions that incorporate the vmwgfx driver before the fix commit are affected. The issue is present in the mainline kernel and, by implication, any distributions that ship with these kernel versions without the patch. Specific version ranges are not listed in the advisory, so all unsupported or older kernels should be treated as vulnerable until the update is applied.
Risk and Exploitability
The threat is considered high due to the CVSS score of 7.8, which indicates a high impact, however the low EPSS score suggests that active exploitation is not widely observed at present. Nonetheless, deployments should not wait for exploitation evidence before mitigating.
OpenCVE Enrichment
Debian DLA