CVE-2025-40277

Severity CVSS v4.0:
Pending analysis
Type:
Unavailable / Other
Publication date:
06/12/2025
Last modified:
06/12/2025

Description

In the Linux kernel, the following vulnerability has been resolved:<br /> <br /> drm/vmwgfx: Validate command header size against SVGA_CMD_MAX_DATASIZE<br /> <br /> This data originates from userspace and is used in buffer offset<br /> calculations which could potentially overflow causing an out-of-bounds<br /> access.

Impact