cbcvebase.
CVE-2025-40110
published 2025-11-12

CVE-2025-40110: In the Linux kernel, the following vulnerability has been resolved: drm/vmwgfx: Fix a null-ptr access in the cursor snooper Check that the resource which is…

PriorityP423high7.8
EPSS
0.19%
8.7th percentile
In the Linux kernel, the following vulnerability has been resolved: drm/vmwgfx: Fix a null-ptr access in the cursor snooper Check that the resource which is converted to a surface exists before trying to use the cursor snooper on it. vmw_cmd_res_check allows explicit invalid (SVGA3D_INVALID_ID) identifiers because some svga commands accept SVGA3D_INVALID_ID to mean "no surface", unfortunately functions that accept the actual surfaces as objects might (and in case of the cursor snooper, do not) be able to handle null objects. Make sure that we validate not only the identifier (via the vmw_cmd_res_check) but also check that the actual resource exists before trying to do something with it. Fixes unchecked null-ptr reference in the snooping code.

Affected

28 ranges· showing 25
VendorProductVersion rangeFixed in
debianlinux< linux 6.1.162-1 (bookworm)linux 6.1.162-1 (bookworm)
debianlinux-6.1< linux 6.1.162-1 (bookworm)linux 6.1.162-1 (bookworm)
linuxlinux
linuxlinux>= c0951b797e7d0f2c6b0df2c0e18185c72d0cf1a1 < 3332212e93d0f6e24f8fe79f975e077c4e68ca393332212e93d0f6e24f8fe79f975e077c4e68ca39
linuxlinux>= c0951b797e7d0f2c6b0df2c0e18185c72d0cf1a1 < 86aae7053d2da3fdfde7b2e84d86e4af5049050586aae7053d2da3fdfde7b2e84d86e4af50490505
linuxlinux>= c0951b797e7d0f2c6b0df2c0e18185c72d0cf1a1 < af9d88cbf0fce52f465978360542ef679713491faf9d88cbf0fce52f465978360542ef679713491f
linuxlinux>= c0951b797e7d0f2c6b0df2c0e18185c72d0cf1a1 < 299cfb5a7deabdf9ecd30071755672af0aced5eb299cfb5a7deabdf9ecd30071755672af0aced5eb
linuxlinux>= c0951b797e7d0f2c6b0df2c0e18185c72d0cf1a1 < 13c9e4ed125e19484234c960efe5ac9c5511952313c9e4ed125e19484234c960efe5ac9c55119523
linuxlinux>= c0951b797e7d0f2c6b0df2c0e18185c72d0cf1a1 < b6fca0a07989f361ceda27cb2d09c555d4d4a964b6fca0a07989f361ceda27cb2d09c555d4d4a964
linuxlinux>= c0951b797e7d0f2c6b0df2c0e18185c72d0cf1a1 < 5ac2c0279053a2c5265d46903432fb26ae2d0da25ac2c0279053a2c5265d46903432fb26ae2d0da2
linuxlinux_kernel>= 0 < 5.10.249-15.10.249-1
linuxlinux_kernel>= 0 < 6.1.162-16.1.162-1
linuxlinux_kernel>= 0 < 6.12.57-16.12.57-1
linuxlinux_kernel>= 0 < 6.17.6-16.17.6-1
linuxlinux_kernel>= 0 < 5.15.0-173.1835.15.0-173.183
linuxlinux_kernel>= 0 < 6.8.0-106.1066.8.0-106.106
linuxlinux_kernel>= 0 < 6.17.0-14.146.17.0-14.14
linuxlinux_kernel>= 3.8.0 < 5.10.2485.10.248
linuxlinux_kernel>= 5.11.0 < 5.15.1985.15.198
linuxlinux_kernel>= 5.16.0 < 6.1.1606.1.160
linuxlinux_kernel>= 6.13.0 < 6.17.46.17.4
linuxlinux_kernel>= 6.2.0 < 6.6.1136.6.113
linuxlinux_kernel>= 6.7.0 < 6.12.546.12.54
msrcazl3_kernel_6.6.112.1-2_on_azure_linux_3.0
ubuntulinux-aws

CVSS provenance

osv7.8HIGH
vendor_ubuntu7.8HIGH
vendor_redhat4.7MEDIUM
vendor_msrc4.1MEDIUM
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.