CVE-2026-23008
Linux Kernel vulnerability analysis and mitigation

Overview

CVE-2026-23008 is a NULL pointer dereference vulnerability in the Linux kernel's drm/vmwgfx graphics driver affecting Kernel Mode Setting (KMS) with 3D graphics on hardware version 10. Because HW version 10 lacks GB Surfaces, there is no backing buffer for surface-backed framebuffers, causing a NULL pointer dereference that crashes the driver and results in a black screen. The vulnerability was published on January 25, 2026, and affects Linux kernel versions 6.16 through 6.18.6 (exclusive), as well as 6.19-rc1 through 6.19-rc8. It carries a CVSS v3.1 base score of 5.5 (Medium) (Red Hat Advisory, Red Hat Bugzilla).

Technical details

The root cause is classified as CWE-476 (NULL Pointer Dereference). When KMS is used with 3D acceleration on VMware hardware version 10, the vmwgfx driver attempts to access a backing buffer (GB Surface) for surface-backed framebuffers that does not exist on that hardware generation, resulting in a null pointer dereference. Exploitation requires local access with low privileges and no user interaction, making it a local denial-of-service condition. Patches are available as kernel commits a91bdd21d5efb3072beefbec13762b7722200c49 and d9186faeae6efb7d0841a5e8eb213ff4c7966614 on the stable kernel tree (Red Hat Advisory, kernel.org patch 1, kernel.org patch 2).

Impact

Successful exploitation causes the vmwgfx graphics driver to crash, resulting in a denial-of-service condition manifesting as a black screen and loss of graphics subsystem functionality. The impact is limited to availability (no confidentiality or integrity impact), and the scope is confined to the local system's graphics subsystem. Lateral movement or data exfiltration are not applicable to this vulnerability given its nature as a driver crash (Red Hat Advisory).

Mitigation and workarounds

Update the Linux kernel to version 6.18.7 or later, which includes the fix via commits a91bdd21d5efb3072beefbec13762b7722200c49 and d9186faeae6efb7d0841a5e8eb213ff4c7966614. For systems that cannot be immediately patched and where the vmwgfx driver is not required, consider blacklisting or disabling the driver module (vmwgfx) as a temporary workaround. Organizations running affected kernel versions (6.16 through 6.18.6, or 6.19-rc1 through 6.19-rc8) should prioritize upgrading (Red Hat Advisory, Red Hat Bugzilla).

Community reactions

Red Hat triaged the vulnerability with low priority and low severity, reflecting its limited exploitability and local-only attack vector (Red Hat Bugzilla). The Yocto Project security mailing list also tracked the issue for embedded Linux distributions (Yocto Security List). No significant broader media coverage or notable researcher commentary has been identified.

Additional resources


SourceThis report was generated using AI

Related Linux Kernel vulnerabilities:

CVE ID

Severity

Score

Technologies

Component name

CISA KEV exploit

Has fix

Published date

CVE-2026-64557NONEN/A
  • Linux Kernel logoLinux Kernel
  • kernel-rt-selftests-internal
NoNoJul 29, 2026
CVE-2026-64556NONEN/A
  • Linux Kernel logoLinux Kernel
  • kernel-64k-devel
NoNoJul 29, 2026
CVE-2026-64555NONEN/A
  • Linux Kernel logoLinux Kernel
  • linux-azure-fde-6.14
NoNoJul 27, 2026
CVE-2026-64554NONEN/A
  • Linux Kernel logoLinux Kernel
  • linux-gcp-6.14
NoYesJul 27, 2026
CVE-2026-64553NONEN/A
  • Linux Kernel logoLinux Kernel
  • kernel-rt-64k-debug-modules-internal
NoYesJul 27, 2026

Free Vulnerability Assessment

Benchmark your Cloud Security Posture

Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.

Request assessment

Get a personalized demo

Ready to see Wiz in action?

"Best User Experience I have ever seen, provides full visibility to cloud workloads."
David EstlickCISO
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
Adam FletcherChief Security Officer
"We know that if Wiz identifies something as critical, it actually is."
Greg PoniatowskiHead of Threat and Vulnerability Management