CVE Database
/

CVE-2025-40277

Back to search

CVE-2025-40277

Published: Dec 6, 2025

Modified: May 11, 2026

PUBLISHED

Description

In the Linux kernel, the following vulnerability has been resolved: drm/vmwgfx: Validate command header size against SVGA_CMD_MAX_DATASIZE This data originates from userspace and is used in buffer offset calculations which could potentially overflow causing an out-of-bounds access.

VendorProductVersions

Linux

Linux

affected
8ce75f8ab9044fe11caaaf2b2c82471023212f9f - < e58559845021c3bad5e094219378b869157fad53
affected
8ce75f8ab9044fe11caaaf2b2c82471023212f9f - < 54d458b244893e47bda52ec3943fdfbc8d7d068b
affected
8ce75f8ab9044fe11caaaf2b2c82471023212f9f - < 709e5c088f9c99a5cf2c1d1c6ce58f2cca7ab173
affected
8ce75f8ab9044fe11caaaf2b2c82471023212f9f - < a3abb54c27b2c393c44362399777ad2f6e1ff17e
affected
8ce75f8ab9044fe11caaaf2b2c82471023212f9f - < b5df9e06eed3df6a4f5c6f8453013b0cabb927b4

+3 more versions

Linux

Linux

affected
4.3
unaffected
0 - < 4.3
unaffected
5.4.302 - <= 5.4.*
unaffected
5.10.247 - <= 5.10.*
unaffected
5.15.197 - <= 5.15.*

+5 more versions

Security Training

Train your team to recognize and prevent security threats with our comprehensive security awareness program.

Start Training

Vulnerability Scanning

Discover vulnerabilities in your applications and infrastructure before attackers do.

Scan Now