CVE-2026-23430
Linux Kernel vulnerability analysis and mitigation

Overview

CVE-2026-23430 is a memory leak vulnerability in the Linux kernel's drm/vmwgfx (VMware graphics driver) component, specifically in the KMS (Kernel Mode Setting) surface dirty tracker. The flaw occurs because the surface's dirty tracker is overwritten rather than properly released, causing memory to not be freed after its effective lifetime. It affects Linux kernel versions 6.16 through 6.18.19, 6.19 through 6.19.9, and 7.0-rc1 through 7.0-rc4. The vulnerability was published on April 3, 2026, and carries a CVSS v3.1 base score of 5.5 (Medium) (Github Advisory, Feedly).

Technical details

The root cause is classified as CWE-401 (Missing Release of Memory after Effective Lifetime): when a KMS surface's dirty tracker is initialized or updated in the drm/vmwgfx driver, the existing tracker object is overwritten without first being freed, resulting in a memory leak. The attack vector is local, requiring low privileges (standard user-level access), with low complexity and no user interaction needed. An unprivileged local user can trigger the leak by performing repeated graphics operations that interact with KMS surface management in the VMware virtual GPU driver. Three patch commits address the issue: 354c8bbf8d1e, 3f300a41a366, and c6cb77c474a3 (Github Advisory, Feedly).

Impact

Successful exploitation results in progressive memory exhaustion on the affected system, with no impact on confidentiality or data integrity. Over time, the leaked memory can cause system performance degradation, application crashes, and ultimately a denial of service condition. The vulnerability is scoped to the local system and does not enable lateral movement or data exfiltration, but systems running graphics-intensive workloads or exposed to untrusted local users are at elevated risk (Github Advisory, Feedly).

Mitigation and workarounds

Upgrade the Linux kernel to a patched version: 6.18.20, 6.19.10, or 7.0-rc5 or later. Patch commits are available at git.kernel.org (commits 354c8bbf8d1e4aa61e580dbe160591feda504e4f, 3f300a41a3668095688aa4551214e8080829fa93, and c6cb77c474a32265e21c4871c7992468bf5e7638). For systems that cannot be immediately patched, restrict local user access to graphics-related subsystems where possible, and monitor for signs of memory exhaustion or unexpected performance degradation (Github Advisory, Feedly).

Community reactions

The vulnerability has been tracked by Tenable (Nessus plugin 311340) and referenced in Yocto Project security mailing lists, indicating routine awareness within the embedded Linux and security scanning communities. Amazon Linux 2023 issued a security advisory (ALAS2023-2026-1596) addressing this CVE. No notable researcher commentary or significant social media discussion has been observed beyond standard vulnerability tracking (Feedly).

Additional resources


SourceThis report was generated using AI

Related Linux Kernel vulnerabilities:

CVE ID

Severity

Score

Technologies

Component name

CISA KEV exploit

Has fix

Published date

CVE-2026-64557NONEN/A
  • Linux Kernel logoLinux Kernel
  • kernel-rt-selftests-internal
NoNoJul 29, 2026
CVE-2026-64556NONEN/A
  • Linux Kernel logoLinux Kernel
  • kernel-64k-devel
NoNoJul 29, 2026
CVE-2026-64555NONEN/A
  • Linux Kernel logoLinux Kernel
  • linux-azure-fde-6.14
NoNoJul 27, 2026
CVE-2026-64554NONEN/A
  • Linux Kernel logoLinux Kernel
  • linux-gcp-6.14
NoYesJul 27, 2026
CVE-2026-64553NONEN/A
  • Linux Kernel logoLinux Kernel
  • kernel-rt-64k-debug-modules-internal
NoYesJul 27, 2026

Free Vulnerability Assessment

Benchmark your Cloud Security Posture

Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.

Request assessment

Get a personalized demo

Ready to see Wiz in action?

"Best User Experience I have ever seen, provides full visibility to cloud workloads."
David EstlickCISO
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
Adam FletcherChief Security Officer
"We know that if Wiz identifies something as critical, it actually is."
Greg PoniatowskiHead of Threat and Vulnerability Management