Answer in brief
CVE-2026-74444 records a Unknown severity vulnerability in drm/vmwgfx: validate DRAW_PRIMITIVES header size before division. The current sources do not mark it as known exploited. The current feed maps Linux/Linux (generic), Linux/Linux (generic). Check affected ranges and fixed versions before updating.
Analysis pending evidence review
HOL Guard separates source facts from reviewed analysis. See the methodology.
A CVSS score is not reported in the current record. The current sources do not mark it as known exploited. Treat this as a source-backed prioritization signal, not a statement about your environment.
Analysis status
Analysis pending evidence review
Factual feed record only; HOL analysis is not approved for indexing. Read the methodology.
The current feed maps Linux/Linux (generic), Linux/Linux (generic). Check affected ranges and fixed versions before updating.
| Package | Affected range | Fixed version |
|---|---|---|
| Linux/Linuxgeneric | >=7a73ba7469cbea631050094fd14f73acebb97cf9 <2666cddf0dd218aa9bd1f99db688d1b532eac21a || >=7a73ba7469cbea631050094fd14f73acebb97cf9 <fc0c02f510e41650df3479f96e257acf87d8a20a || >=7a73ba7469cbea631050094fd14f73acebb97cf9 <dc0be7662b7b0ce28cb5eea864737793ed7b9e70 || >=7a73ba7469cbea631050094fd14f73acebb97cf9 <c77cf8edae2bd3a1599115301cc7c98d0c78e731 || >=7a73ba7469cbea631050094fd14f73acebb97cf9 <85891d174707d8bddcec7a888fb4e1d17def34f3 | 2666cddf0dd218aa9bd1f99db688d1b532eac21a, fc0c02f510e41650df3479f96e257acf87d8a20a, dc0be7662b7b0ce28cb5eea864737793ed7b9e70, c77cf8edae2bd3a1599115301cc7c98d0c78e731, 85891d174707d8bddcec7a888fb4e1d17def34f3 |
| Linux/Linuxgeneric | 2.6.33 | Not reported |
Published upstream
Aug 15, 2026
Evidence: source:cvelist:source_dates:source-dates:recordSource modified
Aug 15, 2026
Evidence: source:cvelist:source_dates:source-dates:recordFirst seen by HOL
Aug 15, 2026
In the Linux kernel, the following vulnerability has been resolved: drm/vmwgfx: validate DRAW_PRIMITIVES header size before division vmw_cmd_draw() computes maxnum = (header->size - sizeof(cmd->body)) / sizeof(*decl); where header->size is u32 and is taken straight from the user-supplied command stream. When header->size is less than sizeof(cmd->body) the unsigned subtraction wraps to nearly 4 GiB, producing a huge maxnum. Any user-controlled cmd->body.numVertexDecls then passes the bound and the loop dereferences decl[i] far past the end of the kernel command bounce buffer, producing an out-of-bounds read of kernel memory. Reject undersized headers up front.
Quoted source text, attributed separately from HOL analysis.
Answer in brief
CVE-2026-74444 records a Unknown severity vulnerability in drm/vmwgfx: validate DRAW_PRIMITIVES header size before division. The current sources do not mark it as known exploited. The current feed maps Linux/Linux (generic), Linux/Linux (generic). Check affected ranges and fixed versions before updating.
Analysis pending evidence review
HOL Guard separates source facts from reviewed analysis. See the methodology.
A CVSS score is not reported in the current record. The current sources do not mark it as known exploited. Treat this as a source-backed prioritization signal, not a statement about your environment.
Analysis status
Analysis pending evidence review
Factual feed record only; HOL analysis is not approved for indexing. Read the methodology.
The current feed maps Linux/Linux (generic), Linux/Linux (generic). Check affected ranges and fixed versions before updating.
| Package | Affected range | Fixed version |
|---|---|---|
| Linux/Linuxgeneric | >=7a73ba7469cbea631050094fd14f73acebb97cf9 <2666cddf0dd218aa9bd1f99db688d1b532eac21a || >=7a73ba7469cbea631050094fd14f73acebb97cf9 <fc0c02f510e41650df3479f96e257acf87d8a20a || >=7a73ba7469cbea631050094fd14f73acebb97cf9 <dc0be7662b7b0ce28cb5eea864737793ed7b9e70 || >=7a73ba7469cbea631050094fd14f73acebb97cf9 <c77cf8edae2bd3a1599115301cc7c98d0c78e731 || >=7a73ba7469cbea631050094fd14f73acebb97cf9 <85891d174707d8bddcec7a888fb4e1d17def34f3 | 2666cddf0dd218aa9bd1f99db688d1b532eac21a, fc0c02f510e41650df3479f96e257acf87d8a20a, dc0be7662b7b0ce28cb5eea864737793ed7b9e70, c77cf8edae2bd3a1599115301cc7c98d0c78e731, 85891d174707d8bddcec7a888fb4e1d17def34f3 |
| Linux/Linuxgeneric | 2.6.33 | Not reported |
Published upstream
Aug 15, 2026
Evidence: source:cvelist:source_dates:source-dates:recordSource modified
Aug 15, 2026
Evidence: source:cvelist:source_dates:source-dates:recordFirst seen by HOL
Aug 15, 2026
In the Linux kernel, the following vulnerability has been resolved: drm/vmwgfx: validate DRAW_PRIMITIVES header size before division vmw_cmd_draw() computes maxnum = (header->size - sizeof(cmd->body)) / sizeof(*decl); where header->size is u32 and is taken straight from the user-supplied command stream. When header->size is less than sizeof(cmd->body) the unsigned subtraction wraps to nearly 4 GiB, producing a huge maxnum. Any user-controlled cmd->body.numVertexDecls then passes the bound and the loop dereferences decl[i] far past the end of the kernel command bounce buffer, producing an out-of-bounds read of kernel memory. Reject undersized headers up front.
Quoted source text, attributed separately from HOL analysis.