CVE-2025-40277

NONE EPSS 25.3%
Published Dec 6, 20256mo ago · Modified Jun 17, 20261w ago
Find Similar
Published Dec 6, 2025 6mo ago
Last Modified Jun 17, 2026 1w ago

Description

In the Linux kernel, the following vulnerability has been resolved: drm/vmwgfx: Validate command header size against SVGA_CMD_MAX_DATASIZE This data originates from userspace and is used in buffer offset calculations which could potentially overflow causing an out-of-bounds access.

Threat Intelligence

EPSS Exploit Probability
25.3% percentile
Exploit & Patch Status
No Known Exploit
No Patch Available

References 8

  • git.kernel.org https://git.kernel.org/stable/c/32b415a9dc2c212e809b7ebc2b14bc3fbda2b9af
  • git.kernel.org https://git.kernel.org/stable/c/54d458b244893e47bda52ec3943fdfbc8d7d068b
  • git.kernel.org https://git.kernel.org/stable/c/5aea2cde03d4247cdcf53f9ab7d0747c9dca1cfc
  • git.kernel.org https://git.kernel.org/stable/c/709e5c088f9c99a5cf2c1d1c6ce58f2cca7ab173
  • git.kernel.org https://git.kernel.org/stable/c/a3abb54c27b2c393c44362399777ad2f6e1ff17e
  • git.kernel.org https://git.kernel.org/stable/c/b5df9e06eed3df6a4f5c6f8453013b0cabb927b4
  • git.kernel.org https://git.kernel.org/stable/c/e58559845021c3bad5e094219378b869157fad53
  • git.kernel.org https://git.kernel.org/stable/c/f3f3a8eb3f0ba799fae057091d8c67cca12d6fa0

Remediation

No remediation data recorded yet

Check vendor advisories and the NVD entry for patch availability.