{"id":"CVE-2022-50440","summary":"drm/vmwgfx: Validate the box size for the snooped cursor","details":"In the Linux kernel, the following vulnerability has been resolved:\n\ndrm/vmwgfx: Validate the box size for the snooped cursor\n\nInvalid userspace dma surface copies could potentially overflow\nthe memcpy from the surface to the snooped image leading to crashes.\nTo fix it the dimensions of the copybox have to be validated\nagainst the expected size of the snooped cursor.","modified":"2026-03-20T11:47:27.733585Z","published":"2025-10-01T11:42:16.567Z","related":["SUSE-SU-2025:03613-1","SUSE-SU-2025:03614-1","SUSE-SU-2025:03615-1","SUSE-SU-2025:03626-1","SUSE-SU-2025:03628-1","SUSE-SU-2025:3716-1","SUSE-SU-2025:3761-1"],"database_specific":{"cna_assigner":"Linux","osv_generated_from":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2022/50xxx/CVE-2022-50440.json"},"references":[{"type":"WEB","url":"https://git.kernel.org/stable/c/439cbbc1519547f9a7b483f0de33b556ebfec901"},{"type":"WEB","url":"https://git.kernel.org/stable/c/4cf949c7fafe21e085a4ee386bb2dade9067316e"},{"type":"WEB","url":"https://git.kernel.org/stable/c/4d54d11b49860686331c58a00f733b16a93edfc4"},{"type":"WEB","url":"https://git.kernel.org/stable/c/50d177f90b63ea4138560e500d92be5e4c928186"},{"type":"WEB","url":"https://git.kernel.org/stable/c/622d527decaac0eb65512acada935a0fdc1d0202"},{"type":"WEB","url":"https://git.kernel.org/stable/c/6948e570f54f2044dd4da444b10471373a047eeb"},{"type":"WEB","url":"https://git.kernel.org/stable/c/6b4e70a428b5a11f56db94047b68e144529fe512"},{"type":"WEB","url":"https://git.kernel.org/stable/c/94b283341f9f3f0ed56a360533766377a01540e0"},{"type":"WEB","url":"https://git.kernel.org/stable/c/ee8d31836cbe7c26e207bfa0a4a726f0a25cfcf6"},{"type":"ADVISORY","url":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2022/50xxx/CVE-2022-50440.json"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2022-50440"},{"type":"PACKAGE","url":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git"}],"affected":[{"ranges":[{"type":"GIT","repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","events":[{"introduced":"2ac863719e518ae1a8f328849e64ea26a222f079"},{"fixed":"ee8d31836cbe7c26e207bfa0a4a726f0a25cfcf6"},{"fixed":"50d177f90b63ea4138560e500d92be5e4c928186"},{"fixed":"6b4e70a428b5a11f56db94047b68e144529fe512"},{"fixed":"94b283341f9f3f0ed56a360533766377a01540e0"},{"fixed":"439cbbc1519547f9a7b483f0de33b556ebfec901"},{"fixed":"6948e570f54f2044dd4da444b10471373a047eeb"},{"fixed":"4d54d11b49860686331c58a00f733b16a93edfc4"},{"fixed":"622d527decaac0eb65512acada935a0fdc1d0202"},{"fixed":"4cf949c7fafe21e085a4ee386bb2dade9067316e"}]}],"database_specific":{"source":"https://storage.googleapis.com/osv-test-cve-osv-conversion/osv-output/CVE-2022-50440.json"}}],"schema_version":"1.7.5"}