cbcvebase.
CVE-2025-40277
published 2025-12-06

CVE-2025-40277: In the Linux kernel, the following vulnerability has been resolved: drm/vmwgfx: Validate command header size against SVGA_CMD_MAX_DATASIZE This data originates…

PriorityP342high7.8CVSS 3.1
AVLACLPRLUINSUCHIHAH
EPSS
0.21%
11.4th percentile
In the Linux kernel, the following vulnerability has been resolved: drm/vmwgfx: Validate command header size against SVGA_CMD_MAX_DATASIZE This data originates from userspace and is used in buffer offset calculations which could potentially overflow causing an out-of-bounds access.

Affected

30 ranges· showing 25
VendorProductVersion rangeFixed in
debianlinux< linux 6.1.159-1 (bookworm)linux 6.1.159-1 (bookworm)
debianlinux-6.1< linux 6.1.159-1 (bookworm)linux 6.1.159-1 (bookworm)
linuxlinux
linuxlinux>= 8ce75f8ab9044fe11caaaf2b2c82471023212f9f < e58559845021c3bad5e094219378b869157fad53e58559845021c3bad5e094219378b869157fad53
linuxlinux>= 8ce75f8ab9044fe11caaaf2b2c82471023212f9f < 54d458b244893e47bda52ec3943fdfbc8d7d068b54d458b244893e47bda52ec3943fdfbc8d7d068b
linuxlinux>= 8ce75f8ab9044fe11caaaf2b2c82471023212f9f < 709e5c088f9c99a5cf2c1d1c6ce58f2cca7ab173709e5c088f9c99a5cf2c1d1c6ce58f2cca7ab173
linuxlinux>= 8ce75f8ab9044fe11caaaf2b2c82471023212f9f < a3abb54c27b2c393c44362399777ad2f6e1ff17ea3abb54c27b2c393c44362399777ad2f6e1ff17e
linuxlinux>= 8ce75f8ab9044fe11caaaf2b2c82471023212f9f < b5df9e06eed3df6a4f5c6f8453013b0cabb927b4b5df9e06eed3df6a4f5c6f8453013b0cabb927b4
linuxlinux>= 8ce75f8ab9044fe11caaaf2b2c82471023212f9f < 5aea2cde03d4247cdcf53f9ab7d0747c9dca1cfc5aea2cde03d4247cdcf53f9ab7d0747c9dca1cfc
linuxlinux>= 8ce75f8ab9044fe11caaaf2b2c82471023212f9f < f3f3a8eb3f0ba799fae057091d8c67cca12d6fa0f3f3a8eb3f0ba799fae057091d8c67cca12d6fa0
linuxlinux>= 8ce75f8ab9044fe11caaaf2b2c82471023212f9f < 32b415a9dc2c212e809b7ebc2b14bc3fbda2b9af32b415a9dc2c212e809b7ebc2b14bc3fbda2b9af
linuxlinux_kernel>= 0 < 5.10.247-15.10.247-1
linuxlinux_kernel>= 0 < 6.1.159-16.1.159-1
linuxlinux_kernel>= 0 < 6.12.63-16.12.63-1
linuxlinux_kernel>= 0 < 6.17.9-16.17.9-1
linuxlinux_kernel>= 0 < 5.15.0-173.1835.15.0-173.183
linuxlinux_kernel>= 0 < 6.8.0-106.1066.8.0-106.106
linuxlinux_kernel>= 0 < 6.17.0-14.146.17.0-14.14
linuxlinux_kernel>= 4.3.0 < 5.4.3025.4.302
linuxlinux_kernel>= 5.11.0 < 5.15.1975.15.197
linuxlinux_kernel>= 5.16.0 < 6.1.1596.1.159
linuxlinux_kernel>= 5.5.0 < 5.10.2475.10.247
linuxlinux_kernel>= 6.13.0 < 6.17.96.17.9
linuxlinux_kernel>= 6.2.0 < 6.6.1176.6.117
linuxlinux_kernel>= 6.7.0 < 6.12.596.12.59

CVSS provenance

nvdv3.17.8HIGHCVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
osv7.8HIGH
vendor_redhat7.8MEDIUM
vendor_ubuntu7.8HIGH
vendor_msrc7.3HIGH
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.