{"schema_version":"1.7.5","id":"CVE-2026-23317","published":"2026-03-25T10:27:11.884Z","modified":"2026-07-15T01:49:21.036540841Z","related":["SUSE-SU-2026:1573-1","SUSE-SU-2026:1574-1","SUSE-SU-2026:1606-1","SUSE-SU-2026:1643-1","SUSE-SU-2026:1661-1","SUSE-SU-2026:21114-1","SUSE-SU-2026:21123-1","SUSE-SU-2026:21255-1","SUSE-SU-2026:2134-1","SUSE-SU-2026:2149-1","SUSE-SU-2026:2159-1","SUSE-SU-2026:2172-1","SUSE-SU-2026:2176-1","SUSE-SU-2026:2181-1","SUSE-SU-2026:21834-1","SUSE-SU-2026:21841-1","SUSE-SU-2026:21845-1","SUSE-SU-2026:21860-1","SUSE-SU-2026:21886-1","SUSE-SU-2026:21887-1","SUSE-SU-2026:21888-1","SUSE-SU-2026:21889-1","SUSE-SU-2026:21890-1","SUSE-SU-2026:21891-1","SUSE-SU-2026:21892-1","SUSE-SU-2026:21893-1","SUSE-SU-2026:21896-1","SUSE-SU-2026:21900-1","SUSE-SU-2026:21901-1","SUSE-SU-2026:21902-1","SUSE-SU-2026:21903-1","SUSE-SU-2026:21904-1","SUSE-SU-2026:21905-1","SUSE-SU-2026:21906-1","SUSE-SU-2026:21907-1","SUSE-SU-2026:21910-1","SUSE-SU-2026:21921-1","SUSE-SU-2026:21922-1","SUSE-SU-2026:21923-1","SUSE-SU-2026:21924-1","SUSE-SU-2026:21925-1","SUSE-SU-2026:21926-1","SUSE-SU-2026:21927-1","SUSE-SU-2026:21928-1","SUSE-SU-2026:21929-1","SUSE-SU-2026:21932-1","SUSE-SU-2026:21933-1","SUSE-SU-2026:21934-1","SUSE-SU-2026:21935-1","SUSE-SU-2026:21936-1","SUSE-SU-2026:21937-1","SUSE-SU-2026:21938-1","SUSE-SU-2026:21939-1","SUSE-SU-2026:21942-1","SUSE-SU-2026:21958-1","SUSE-SU-2026:21959-1","SUSE-SU-2026:21960-1","SUSE-SU-2026:21962-1","SUSE-SU-2026:21963-1","SUSE-SU-2026:21969-1","SUSE-SU-2026:21970-1","SUSE-SU-2026:21972-1","SUSE-SU-2026:21979-1","SUSE-SU-2026:21982-1","SUSE-SU-2026:21983-1","SUSE-SU-2026:2199-1","SUSE-SU-2026:22030-1","SUSE-SU-2026:22031-1","SUSE-SU-2026:22033-1","SUSE-SU-2026:22038-1","SUSE-SU-2026:22039-1","SUSE-SU-2026:22040-1","SUSE-SU-2026:22042-1","openSUSE-SU-2026:20826-1"],"summary":"drm/vmwgfx: Return the correct value in vmw_translate_ptr functions","details":"In the Linux kernel, the following vulnerability has been resolved:\n\ndrm/vmwgfx: Return the correct value in vmw_translate_ptr functions\n\nBefore the referenced fixes these functions used a lookup function that\nreturned a pointer. This was changed to another lookup function that\nreturned an error code with the pointer becoming an out parameter.\n\nThe error path when the lookup failed was not changed to reflect this\nchange and the code continued to return the PTR_ERR of the now\nuninitialized pointer. This could cause the vmw_translate_ptr functions\nto return success when they actually failed causing further uninitialized\nand OOB accesses.","affected":[{"ranges":[{"type":"GIT","repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","events":[{"introduced":"7ac9578e45b20e3f3c0c8eb71f5417a499a7226a"},{"fixed":"ce3a5cf139787c186d5d54336107298cacaad2b9"}]},{"type":"GIT","repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","events":[{"introduced":"a309c7194e8a2f8bd4539b9449917913f6c2cd50"},{"fixed":"7e55d0788b362c93660b80cc5603031bbbdefa98"},{"fixed":"36cb28b6d303a81e6ed4536017090e85e0143e42"},{"fixed":"531f45589787799aa81b63e1e1f8e71db5d93dd1"},{"fixed":"149f028772fa2879d9316b924ce948a6a0877e45"},{"fixed":"5023ca80f9589295cb60735016e39fc5cc714243"}]},{"type":"GIT","repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","events":[{"introduced":"6.1.7"},{"fixed":"6.1.167"}]}],"versions":["v6.1.166","v6.1.165","v6.1.164","v6.1.163","v6.1.162","v6.1.161","v6.1.160","v6.1.159","v6.1.158","v6.1.157","v6.1.156","v6.1.155","v6.1.154","v6.1.153","v6.1.152","v6.1.151","v6.1.150","v6.1.149","v6.1.148","v6.1.147","v6.1.146","v6.1.145","v6.1.144","v6.1.143","v6.1.142","v6.1.141","v6.1.140","v6.1.139","v6.1.138","v6.1.137","v6.1.136","v6.1.135","v6.1.134","v6.1.133","v6.1.132","v6.1.131","v6.1.130","v6.1.129","v6.1.128","v6.1.127","v6.1.126","v6.1.125","v6.1.124","v6.1.123","v6.1.122","v6.1.121","v6.1.120","v6.1.119","v6.1.118","v6.1.117","v6.1.116","v6.1.115","v6.1.114","v6.1.113","v6.1.112","v6.1.111","v6.1.110","v6.1.109","v6.1.108","v6.1.107","v6.1.106","v6.1.105","v6.1.104","v6.1.103","v6.1.102","v6.1.101","v6.1.100","v6.1.99","v6.1.98","v6.1.97","v6.1.96","v6.1.95","v6.1.94","v6.1.93","v6.1.92","v6.1.91","v6.1.90","v6.1.89","v6.1.88","v6.1.87","v6.1.86","v6.1.85","v6.1.84","v6.1.83","v6.1.82","v6.1.81","v6.1.80","v6.1.79","v6.1.78","v6.1.77","v6.1.76","v6.1.75","v6.1.74","v6.1.73","v6.1.72","v6.1.71","v6.1.70","v6.1.69","v6.1.68","v6.1.67","v6.1.66","v6.1.65","v6.1.64","v6.1.63","v6.1.62","v6.1.61","v6.1.60","v6.1.59","v6.1.58","v6.1.57","v6.1.56","v6.1.55","v6.1.54","v6.1.53","v6.1.52","v6.1.51","v6.1.50","v6.1.49","v6.1.48","v6.1.47","v6.1.46","v6.1.45","v6.1.44","v6.1.43","v6.1.42","v6.1.41","v6.1.40","v6.1.39","v6.1.38","v6.1.37","v6.1.36","v6.1.35","v6.1.34","v6.1.33","v6.1.32","v6.1.31","v6.1.30","v6.1.29","v6.1.28","v6.1.27","v6.1.26","v6.1.25","v6.1.24","v6.1.23","v6.1.22","v6.1.21","v6.1.20","v6.1.19","v6.1.18","v6.1.17","v6.1.16","v6.1.15","v6.1.14","v6.1.13","v6.1.12","v6.1.11","v6.1.10","v6.1.9","v6.1.8","v6.1.7"],"database_specific":{"source":"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-23317.json"}},{"package":{"name":"Kernel","ecosystem":"Linux"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"6.1.167"}]},{"type":"ECOSYSTEM","events":[{"introduced":"6.2.0"},{"fixed":"6.6.130"},{"fixed":"6.12.77"}]},{"type":"ECOSYSTEM","events":[{"introduced":"6.7.0"},{"fixed":"6.18.17"}]},{"type":"ECOSYSTEM","events":[{"introduced":"6.13.0"},{"fixed":"6.19.7"}]}],"database_specific":{"source":"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-23317.json"}}],"references":[{"type":"WEB","url":"https://git.kernel.org/stable/c/149f028772fa2879d9316b924ce948a6a0877e45"},{"type":"WEB","url":"https://git.kernel.org/stable/c/36cb28b6d303a81e6ed4536017090e85e0143e42"},{"type":"WEB","url":"https://git.kernel.org/stable/c/5023ca80f9589295cb60735016e39fc5cc714243"},{"type":"WEB","url":"https://git.kernel.org/stable/c/531f45589787799aa81b63e1e1f8e71db5d93dd1"},{"type":"WEB","url":"https://git.kernel.org/stable/c/7e55d0788b362c93660b80cc5603031bbbdefa98"},{"type":"WEB","url":"https://git.kernel.org/stable/c/ce3a5cf139787c186d5d54336107298cacaad2b9"},{"type":"ADVISORY","url":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/23xxx/CVE-2026-23317.json"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-23317"},{"type":"PACKAGE","url":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git"}],"database_specific":{"cna_assigner":"Linux","osv_generated_from":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/23xxx/CVE-2026-23317.json"},"severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H"}]}