-
CVE-2025-40277
- EPSS 0.08%
- Veröffentlicht 06.12.2025 21:51:00
- Zuletzt bearbeitet 15.04.2026 00:35:42
- Quelle 416baaa9-dc9f-4396-8d5f-8c081f
- CVE-Watchlists
- Unerledigt
drm/vmwgfx: Validate command header size against SVGA_CMD_MAX_DATASIZE
In the Linux kernel, the following vulnerability has been resolved: drm/vmwgfx: Validate command header size against SVGA_CMD_MAX_DATASIZE This data originates from userspace and is used in buffer offset calculations which could potentially overflow causing an out-of-bounds access.
Daten sind bereitgestellt durch das CVE Programm von einer CVE Numbering Authority (CNA) (Unstrukturiert).
HerstellerLinux
≫
Produkt
Linux
Default Statusunaffected
Version
8ce75f8ab9044fe11caaaf2b2c82471023212f9f
Version <
e58559845021c3bad5e094219378b869157fad53
Status
affected
Version
8ce75f8ab9044fe11caaaf2b2c82471023212f9f
Version <
54d458b244893e47bda52ec3943fdfbc8d7d068b
Status
affected
Version
8ce75f8ab9044fe11caaaf2b2c82471023212f9f
Version <
709e5c088f9c99a5cf2c1d1c6ce58f2cca7ab173
Status
affected
Version
8ce75f8ab9044fe11caaaf2b2c82471023212f9f
Version <
a3abb54c27b2c393c44362399777ad2f6e1ff17e
Status
affected
Version
8ce75f8ab9044fe11caaaf2b2c82471023212f9f
Version <
b5df9e06eed3df6a4f5c6f8453013b0cabb927b4
Status
affected
Version
8ce75f8ab9044fe11caaaf2b2c82471023212f9f
Version <
5aea2cde03d4247cdcf53f9ab7d0747c9dca1cfc
Status
affected
Version
8ce75f8ab9044fe11caaaf2b2c82471023212f9f
Version <
f3f3a8eb3f0ba799fae057091d8c67cca12d6fa0
Status
affected
Version
8ce75f8ab9044fe11caaaf2b2c82471023212f9f
Version <
32b415a9dc2c212e809b7ebc2b14bc3fbda2b9af
Status
affected
HerstellerLinux
≫
Produkt
Linux
Default Statusaffected
Version
4.3
Status
affected
Version
0
Version <
4.3
Status
unaffected
Version <=
5.4.*
Version
5.4.302
Status
unaffected
Version <=
5.10.*
Version
5.10.247
Status
unaffected
Version <=
5.15.*
Version
5.15.197
Status
unaffected
Version <=
6.1.*
Version
6.1.159
Status
unaffected
Version <=
6.6.*
Version
6.6.117
Status
unaffected
Version <=
6.12.*
Version
6.12.59
Status
unaffected
Version <=
6.17.*
Version
6.17.9
Status
unaffected
Version <=
*
Version
6.18
Status
unaffected
VulnDex Vulnerability Enrichment
| Typ | Quelle | Score | Percentile |
|---|---|---|---|
| EPSS | FIRST.org | 0.08% | 0.24 |
| Quelle | Base Score | Exploit Score | Impact Score | Vector String |
|---|