CVE-2025-40334 — Improper Validation of Specified Index, Position, or Offset in Input in Linux
CWE-1285 — Improper Validation of Specified Index, Position, or Offset in Input17 documents8 sources
Severity
5.5MEDIUM
No vectorEPSS
0.0%
top 89.68%
CISA KEV
Not in KEV
Exploit
No known exploits
Affected products
Timeline
PublishedDec 9
Latest updateFeb 24
Description
In the Linux kernel, the following vulnerability has been resolved:
drm/amdgpu: validate userq buffer virtual address and size
It needs to validate the userq object virtual address to
determine whether it is residented in a valid vm mapping.
Affected Packages6 packages
▶CVEListV5linux/linux5501117d24a38dadff3dbd8d3102559b27929668 — 5a577de86c4a1c67ca405571d6ef84e65c6897d1+3