cbcvebase.
CVE-2025-40011
published 2025-10-20

CVE-2025-40011: In the Linux kernel, the following vulnerability has been resolved: drm/gma500: Fix null dereference in hdmi teardown pci_set_drvdata sets the value of…

PriorityP420high7.8
EPSS
0.24%
15.4th percentile
In the Linux kernel, the following vulnerability has been resolved: drm/gma500: Fix null dereference in hdmi teardown pci_set_drvdata sets the value of pdev->driver_data to NULL, after which the driver_data obtained from the same dev is dereferenced in oaktrail_hdmi_i2c_exit, and the i2c_dev is extracted from it. To prevent this, swap these calls. Found by Linux Verification Center (linuxtesting.org) with Svacer.

Affected

30 ranges· showing 25
VendorProductVersion rangeFixed in
debianlinux< linux 6.1.158-1 (bookworm)linux 6.1.158-1 (bookworm)
debianlinux-6.1< linux 6.1.158-1 (bookworm)linux 6.1.158-1 (bookworm)
linuxlinux
linuxlinux>= 1b082ccf5901108d3acd860a73d8c0442556c0bb < 70b0c11483d3b90b2d0f416026e475e084a77e6270b0c11483d3b90b2d0f416026e475e084a77e62
linuxlinux>= 1b082ccf5901108d3acd860a73d8c0442556c0bb < 4bbfd1b290857b9d14ea9d91562bde55ff2bc85e4bbfd1b290857b9d14ea9d91562bde55ff2bc85e
linuxlinux>= 1b082ccf5901108d3acd860a73d8c0442556c0bb < e15de80737d444ed743b1c60ced4a3a97913169be15de80737d444ed743b1c60ced4a3a97913169b
linuxlinux>= 1b082ccf5901108d3acd860a73d8c0442556c0bb < 02e4ff4941efb9bbb40d8d5b61efa1a4119b1ba702e4ff4941efb9bbb40d8d5b61efa1a4119b1ba7
linuxlinux>= 1b082ccf5901108d3acd860a73d8c0442556c0bb < 6ffa6b5bc861a3ea9dfcdc007f002b4a347c24ba6ffa6b5bc861a3ea9dfcdc007f002b4a347c24ba
linuxlinux>= 1b082ccf5901108d3acd860a73d8c0442556c0bb < f800f7054d2cf28b51296c7c575da27c29e3859bf800f7054d2cf28b51296c7c575da27c29e3859b
linuxlinux>= 1b082ccf5901108d3acd860a73d8c0442556c0bb < 0fc650fa475b50c1da8236c5e900b9460c7027bc0fc650fa475b50c1da8236c5e900b9460c7027bc
linuxlinux>= 1b082ccf5901108d3acd860a73d8c0442556c0bb < 352e66900cde63f3dadb142364d3c35170bbaaff352e66900cde63f3dadb142364d3c35170bbaaff
linuxlinux_kernel>= 0 < 5.10.247-15.10.247-1
linuxlinux_kernel>= 0 < 6.1.158-16.1.158-1
linuxlinux_kernel>= 0 < 6.12.57-16.12.57-1
linuxlinux_kernel>= 0 < 6.16.10-16.16.10-1
linuxlinux_kernel>= 0 < 5.15.0-170.1805.15.0-170.180
linuxlinux_kernel>= 0 < 6.8.0-106.1066.8.0-106.106
linuxlinux_kernel>= 3.3.0 < 5.4.3005.4.300
linuxlinux_kernel>= 5.11.0 < 5.15.1945.15.194
linuxlinux_kernel>= 5.16.0 < 6.1.1556.1.155
linuxlinux_kernel>= 5.5.0 < 5.10.2455.10.245
linuxlinux_kernel>= 6.13.0 < 6.16.106.16.10
linuxlinux_kernel>= 6.2.0 < 6.6.1096.6.109
linuxlinux_kernel>= 6.7.0 < 6.12.506.12.50
msrcazl3_kernel_6.6.104.2-4_on_azure_linux_3.0

CVSS provenance

osv7.8HIGH
vendor_ubuntu7.8HIGH
vendor_msrc5.5MEDIUM
vendor_redhat4.7MEDIUM
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.