CVE-2025-40110 — NULL Pointer Dereference in Linux
Severity
7.8HIGHOSV
OSV3.2
No vectorEPSS
0.0%
top 87.20%
CISA KEV
Not in KEV
Exploit
No known exploits
Affected products
Timeline
PublishedNov 12
Latest updateApr 13
Description
In the Linux kernel, the following vulnerability has been resolved:
drm/vmwgfx: Fix a null-ptr access in the cursor snooper
Check that the resource which is converted to a surface exists before
trying to use the cursor snooper on it.
vmw_cmd_res_check allows explicit invalid (SVGA3D_INVALID_ID) identifiers
because some svga commands accept SVGA3D_INVALID_ID to mean "no surface",
unfortunately functions that accept the actual surfaces as objects might
(and in case of the cursor snooper, do not…
Affected Packages7 packages
▶CVEListV5linux/linuxc0951b797e7d0f2c6b0df2c0e18185c72d0cf1a1 — 3332212e93d0f6e24f8fe79f975e077c4e68ca39+7