CVE-2025-40277

Linux Kernel Buffer Overflow via DRM VMWGFX Command Header

Title source: llm
STIX 2.1

Description

In the Linux kernel, the following vulnerability has been resolved: drm/vmwgfx: Validate command header size against SVGA_CMD_MAX_DATASIZE This data originates from userspace and is used in buffer offset calculations which could potentially overflow causing an out-of-bounds access.

Scores

EPSS 0.0008
EPSS Percentile 24.1%

Details

Status published
Products (25)
linux/Kernel 4.3.0 - 5.4.302linux
linux/Kernel 5.11.0 - 5.15.197linux
linux/Kernel 5.16.0 - 6.1.159linux
linux/Kernel 5.5.0 - 5.10.247linux
linux/Kernel 6.13.0 - 6.17.9linux
linux/Kernel 6.2.0 - 6.6.117linux
linux/Kernel 6.7.0 - 6.12.59linux
Linux/Linux < 4.3
Linux/Linux 4.3
Linux/Linux 5.10.247 - 5.10.*
... and 15 more
Published Dec 06, 2025
Tracked Since Feb 18, 2026