PT-2026-20427 · Vmware+4 · Vmware+4

Published

2026-01-01

·

Updated

2026-05-26

·

CVE-2026-23215

CVSS v3.1

5.5

Medium

VectorAV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
Name of the Vulnerable Software and Affected Versions Linux kernel (affected versions not specified)
Description The Linux kernel contains a flaw related to hypercall clobbers within the x86/vmware component. Specifically, the QEMU VMware mouse emulation incorrectly clears the upper 32 bits of the rdi register, which the kernel uses to store a pointer. This results in a page fault when the register is dereferenced after a hypercall, such as vmware hypercall3() and vmware hypercall4(). The issue stems from the QEMU vmmouse driver saving and restoring register state using a "uint32 t data[6]" array, leading to the loss of the upper bits of the register value. The kernel workaround marks rdi and rsi as clobbered for the affected hypercalls to prevent the issue.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Exploit

Related Identifiers

CVE-2026-23215
ECHO-8496-18B3-842E
OPENSUSE-SU-2026:20572-1
SUSE-SU-2026:1573-1
SUSE-SU-2026:1661-1
SUSE-SU-2026:21237-1
SUSE-SU-2026:21352-1
SUSE-SU-2026:21361-1
USN-8278-1
USN-8278-2
USN-8289-1
USN-8289-2
USN-8296-1
USN-8296-2

Affected Products

Linuxmint
Linux Kernel
Qemu
Ubuntu
Vmware