Cursor Size Limitation Vulnerability in Linux Kernel Graphics Driver by VMware
CVE-2026-80701
What is CVE-2026-80701?
A vulnerability in the Linux kernel graphics driver by VMware allows for oversized mobile (MOB) cursor dimensions, which can lead to unexpected behavior. The drm/vmwgfx driver does not enforce proper boundaries for cursor sizes when using the SVGA_CAP2_CURSOR_MOB update path. This can allow malicious users to request a cursor size that exceeds permitted dimensions, potentially causing system instability. By refining the atomic check for MOB-backed cursor updates, the vulnerability can be mitigated, ensuring that oversized cursor requests are correctly rejected, thus maintaining system integrity.
Affected Version(s)
Linux 965544150d1cadf0e8f5bb6c13c19697e46e1429 < 1eb4f796695be39e0b5c4383350033ced9ade703
Linux 965544150d1cadf0e8f5bb6c13c19697e46e1429 < 9109b7935b9c058b75348610ef8437c52f9020e3
Linux 965544150d1cadf0e8f5bb6c13c19697e46e1429