cbcvebase.
CVE-2025-40354
published 2025-12-16

CVE-2025-40354: In the Linux kernel, the following vulnerability has been resolved: drm/amd/display: increase max link count and fix link->enc NULL pointer access [why] 1.)…

PriorityP337high7.8CVSS 3.1
AVLACLPRLUINSUCHIHAH
EPSS
0.13%
3.2th percentile
In the Linux kernel, the following vulnerability has been resolved: drm/amd/display: increase max link count and fix link->enc NULL pointer access [why] 1.) dc->links[MAX_LINKS] array size smaller than actual requested. max_connector + max_dpia + 4 virtual = 14. increase from 12 to 14. 2.) hw_init() access null LINK_ENC for dpia non display_endpoint. (cherry picked from commit d7f5a61e1b04ed87b008c8d327649d184dc5bb45)

Affected

14 ranges
VendorProductVersion rangeFixed in
debianlinux< linux 6.17.6-1 (forky)linux 6.17.6-1 (forky)
linuxlinux
linuxlinux>= 4562236b3bc0a28aeb6ee93b2d8a849a4c4e1c7c < f28092be4e12b7df9e4f415d25bf0d767bc2d9edf28092be4e12b7df9e4f415d25bf0d767bc2d9ed
linuxlinux>= 4562236b3bc0a28aeb6ee93b2d8a849a4c4e1c7c < a3fc0d36cfb927f8986b83bf5fba47dbedad3c63a3fc0d36cfb927f8986b83bf5fba47dbedad3c63
linuxlinux>= 4562236b3bc0a28aeb6ee93b2d8a849a4c4e1c7c < bec947cbe9a65783adb475a5fb47980d7b4f4796bec947cbe9a65783adb475a5fb47980d7b4f4796
linuxlinux_kernel>= 0 < 6.12.57-16.12.57-1
linuxlinux_kernel>= 0 < 6.17.6-16.17.6-1
linuxlinux_kernel>= 0 < 6.17.0-14.146.17.0-14.14
linuxlinux_kernel>= 4.15.0 < 6.12.566.12.56
linuxlinux_kernel>= 6.13.0 < 6.17.66.17.6
msrcazl3_kernel_6.6.117.1-1_on_azure_linux_3.0
msrcazl3_kernel_6.6.119.3-1_on_azure_linux_3.0
ubuntulinux-aws
ubuntulinux-oracle

CVSS provenance

nvdv3.17.8HIGHCVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
vendor_msrc6.8MEDIUM
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.