CVE-2022-50440
MEDIUMLinux Kernel - Use-After-Free in DRM vmwgfx Snooped Cursor Handling
Title source: llmDescription
In the Linux kernel, the following vulnerability has been resolved: drm/vmwgfx: Validate the box size for the snooped cursor Invalid userspace dma surface copies could potentially overflow the memcpy from the surface to the snooped image leading to crashes. To fix it the dimensions of the copybox have to be validated against the expected size of the snooped cursor.
References (9)
Core 9
Core References
Scores
CVSS v3
5.5
EPSS
0.0015
EPSS Percentile
4.5%
Attack Vector
LOCAL
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
Details
CWE
CWE-476
Status
published
Products (29)
linux/Kernel
3.2.0 - 4.9.337linux
linux/Kernel
4.10.0 - 4.14.303linux
linux/Kernel
4.15.0 - 4.19.270linux
linux/Kernel
4.20.0 - 5.4.229linux
linux/Kernel
5.11.0 - 5.15.87linux
linux/Kernel
5.16.0 - 6.0.18linux
linux/Kernel
5.5.0 - 5.10.163linux
linux/Kernel
6.1.0 - 6.1.4linux
Linux/Linux
< 3.2
Linux/Linux
2ac863719e518ae1a8f328849e64ea26a222f079 - 439cbbc1519547f9a7b483f0de33b556ebfec901
... and 19 more
Published
Oct 01, 2025
Tracked Since
Feb 18, 2026