Home

Description

In the Linux kernel, the following vulnerability has been resolved: drm/vmwgfx: Validate command header size against SVGA_CMD_MAX_DATASIZE This data originates from userspace and is used in buffer offset calculations which could potentially overflow causing an out-of-bounds access.

PUBLISHED Reserved 2025-04-16 | Published 2025-12-06 | Updated 2025-12-06 | Assigner Linux

Product status

Default status
unaffected

8ce75f8ab9044fe11caaaf2b2c82471023212f9f (git) before e58559845021c3bad5e094219378b869157fad53
affected

8ce75f8ab9044fe11caaaf2b2c82471023212f9f (git) before 54d458b244893e47bda52ec3943fdfbc8d7d068b
affected

8ce75f8ab9044fe11caaaf2b2c82471023212f9f (git) before 709e5c088f9c99a5cf2c1d1c6ce58f2cca7ab173
affected

8ce75f8ab9044fe11caaaf2b2c82471023212f9f (git) before a3abb54c27b2c393c44362399777ad2f6e1ff17e
affected

8ce75f8ab9044fe11caaaf2b2c82471023212f9f (git) before b5df9e06eed3df6a4f5c6f8453013b0cabb927b4
affected

8ce75f8ab9044fe11caaaf2b2c82471023212f9f (git) before 5aea2cde03d4247cdcf53f9ab7d0747c9dca1cfc
affected

8ce75f8ab9044fe11caaaf2b2c82471023212f9f (git) before f3f3a8eb3f0ba799fae057091d8c67cca12d6fa0
affected

8ce75f8ab9044fe11caaaf2b2c82471023212f9f (git) before 32b415a9dc2c212e809b7ebc2b14bc3fbda2b9af
affected

Default status
affected

4.3
affected

Any version before 4.3
unaffected

5.4.302 (semver)
unaffected

5.10.247 (semver)
unaffected

5.15.197 (semver)
unaffected

6.1.159 (semver)
unaffected

6.6.117 (semver)
unaffected

6.12.59 (semver)
unaffected

6.17.9 (semver)
unaffected

6.18 (original_commit_for_fix)
unaffected

References

git.kernel.org/...c/e58559845021c3bad5e094219378b869157fad53

git.kernel.org/...c/54d458b244893e47bda52ec3943fdfbc8d7d068b

git.kernel.org/...c/709e5c088f9c99a5cf2c1d1c6ce58f2cca7ab173

git.kernel.org/...c/a3abb54c27b2c393c44362399777ad2f6e1ff17e

git.kernel.org/...c/b5df9e06eed3df6a4f5c6f8453013b0cabb927b4

git.kernel.org/...c/5aea2cde03d4247cdcf53f9ab7d0747c9dca1cfc

git.kernel.org/...c/f3f3a8eb3f0ba799fae057091d8c67cca12d6fa0

git.kernel.org/...c/32b415a9dc2c212e809b7ebc2b14bc3fbda2b9af

cve.org (CVE-2025-40277)

nvd.nist.gov (CVE-2025-40277)

Download JSON