cbcvebase.
CVE-2025-40334
published 2025-12-09

CVE-2025-40334: In the Linux kernel, the following vulnerability has been resolved: drm/amdgpu: validate userq buffer virtual address and size It needs to validate the userq…

PriorityP434high7.3CVSS 3.1
AVLACLPRLUINSUCLIHAH
EPSS
0.15%
4.5th percentile
In the Linux kernel, the following vulnerability has been resolved: drm/amdgpu: validate userq buffer virtual address and size It needs to validate the userq object virtual address to determine whether it is residented in a valid vm mapping.

Affected

11 ranges
VendorProductVersion rangeFixed in
debianlinux< linux 6.17.8-1 (forky)linux 6.17.8-1 (forky)
linuxlinux
linuxlinux>= 5501117d24a38dadff3dbd8d3102559b27929668 < 5a577de86c4a1c67ca405571d6ef84e65c6897d15a577de86c4a1c67ca405571d6ef84e65c6897d1
linuxlinux>= 5501117d24a38dadff3dbd8d3102559b27929668 < 9e46b8bb0539d7bc9a9e7b3072fa4f60824903929e46b8bb0539d7bc9a9e7b3072fa4f6082490392
linuxlinux>= fbf136b932358da1c65eb6fedd064a33a7a96aaa < 9e46b8bb0539d7bc9a9e7b3072fa4f60824903929e46b8bb0539d7bc9a9e7b3072fa4f6082490392
linuxlinux_kernel>= 0 < 6.17.8-16.17.8-1
linuxlinux_kernel>= 0 < 6.17.0-14.146.17.0-14.14
linuxlinux_kernel>= 6.16.0 < 6.17.86.17.8
msrcazl3_kernel_6.6.117.1-1_on_azure_linux_3.0
ubuntulinux-aws
ubuntulinux-oracle

CVSS provenance

nvdv3.17.3HIGHCVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:L/I:H/A:H
vendor_msrc5.5MEDIUM
vendor_redhat5.5MEDIUM
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.