
Cloud Vulnerability DB
A community-led vulnerabilities database
CVE-2026-23008 is a NULL pointer dereference vulnerability in the Linux kernel's drm/vmwgfx graphics driver affecting Kernel Mode Setting (KMS) with 3D graphics on hardware version 10. Because HW version 10 lacks GB Surfaces, there is no backing buffer for surface-backed framebuffers, causing a NULL pointer dereference that crashes the driver and results in a black screen. The vulnerability was published on January 25, 2026, and affects Linux kernel versions 6.16 through 6.18.6 (exclusive), as well as 6.19-rc1 through 6.19-rc8. It carries a CVSS v3.1 base score of 5.5 (Medium) (Red Hat Advisory, Red Hat Bugzilla).
The root cause is classified as CWE-476 (NULL Pointer Dereference). When KMS is used with 3D acceleration on VMware hardware version 10, the vmwgfx driver attempts to access a backing buffer (GB Surface) for surface-backed framebuffers that does not exist on that hardware generation, resulting in a null pointer dereference. Exploitation requires local access with low privileges and no user interaction, making it a local denial-of-service condition. Patches are available as kernel commits a91bdd21d5efb3072beefbec13762b7722200c49 and d9186faeae6efb7d0841a5e8eb213ff4c7966614 on the stable kernel tree (Red Hat Advisory, kernel.org patch 1, kernel.org patch 2).
Successful exploitation causes the vmwgfx graphics driver to crash, resulting in a denial-of-service condition manifesting as a black screen and loss of graphics subsystem functionality. The impact is limited to availability (no confidentiality or integrity impact), and the scope is confined to the local system's graphics subsystem. Lateral movement or data exfiltration are not applicable to this vulnerability given its nature as a driver crash (Red Hat Advisory).
Update the Linux kernel to version 6.18.7 or later, which includes the fix via commits a91bdd21d5efb3072beefbec13762b7722200c49 and d9186faeae6efb7d0841a5e8eb213ff4c7966614. For systems that cannot be immediately patched and where the vmwgfx driver is not required, consider blacklisting or disabling the driver module (vmwgfx) as a temporary workaround. Organizations running affected kernel versions (6.16 through 6.18.6, or 6.19-rc1 through 6.19-rc8) should prioritize upgrading (Red Hat Advisory, Red Hat Bugzilla).
Red Hat triaged the vulnerability with low priority and low severity, reflecting its limited exploitability and local-only attack vector (Red Hat Bugzilla). The Yocto Project security mailing list also tracked the issue for embedded Linux distributions (Yocto Security List). No significant broader media coverage or notable researcher commentary has been identified.
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."