CVE-2025-0010 — Out-of-bounds Write in Kernel
CWE-787 — Out-of-bounds WriteCWE-459 — Incomplete CleanupCWE-704 — Incorrect Type Conversion or CastCWE-416 — Use After FreeCWE-1341 — Multiple Releases of Same Resource or HandleCWE-400 — Uncontrolled Resource ConsumptionCWE-99 — Resource InjectionCWE-131 — Incorrect Calculation of Buffer SizeCWE-476 — NULL Pointer Dereference42 documents7 sources
Severity
6.1MEDIUMNVD
EPSS
0.0%
top 97.40%
CISA KEV
Not in KEV
Exploit
No known exploits
Affected products
Timeline
PublishedSep 6
Latest updateJan 23
Description
An out of bounds write in the Linux graphics driver could allow an attacker to overflow the buffer potentially resulting in loss of confidentiality, integrity, or availability.
CVSS vector
CVSS:3.1/AV:L/AC:L/PR:L/UI:R/S:U/C:L/I:L/A:HExploitability: 1.3 | Impact: 4.7
Affected Packages2 packages
🔴Vulnerability Details
4GHSA▶
GHSA-8hgc-v7h6-7v8j: An out of bounds write in the Linux graphics driver could allow an attacker to overflow the buffer potentially resulting in loss of confidentiality, i↗2025-09-06
📋Vendor Advisories
6Red Hat
▶