PT-2026-72895 · Linux · Linux Kernel

CVE-2026-74443

·

Published

2026-08-15

·

Updated

2026-08-18

CVSS v3.1

8.8

High

VectorAV:L/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Linux kernel (affected versions not specified)
Description An issue exists in the vmw cmd dma() function where the DMA suffix location is calculated without verifying if header->size is sufficient to contain both the cmd->body and the suffix. This lack of validation can lead to a pointer underflow, allowing the suffix pointer to reference a previous command in the bounce buffer. Consequently, the verifier may overwrite the maximumOffset of the suffix, resulting in a Time-of-Check to Time-of-Use (TOCTOU) condition on the device-visible command stream. This allows one command to modify authenticated fields of another command, such as the GMR id or surface id.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Exploit

Found an issue in the description? Have something to add? Feel free to write us 👾

Related Identifiers

AZL-96336
CVE-2026-74443

Affected Products

Linux Kernel