CVE-2025-40277
In the Linux kernel, the following vulnerability has been resolved: drm/vmwgfx: Validate command header size against SVGA_CMD_MAX_DATASIZE
CVSS
7.8
High
EPSS
0.2%
p14
KEV
—
Exploit Today
4
0-100
Published: Dec 6, 2025 · Last modified: Jul 30, 2026
0.2%EPSS · 30 days0.3%
2026-07-282026-08-24
In the Linux kernel, the following vulnerability has been resolved: drm/vmwgfx: Validate command header size against SVGA_CMD_MAX_DATASIZE This data originates from userspace and is used in buffer offset calculations which could potentially overflow causing an out-of-bounds access.
- git.kernel.orghttps://git.kernel.org/stable/c/32b415a9dc2c212e809b7ebc2b14bc3fbda2b9af
- git.kernel.orghttps://git.kernel.org/stable/c/54d458b244893e47bda52ec3943fdfbc8d7d068b
- git.kernel.orghttps://git.kernel.org/stable/c/5aea2cde03d4247cdcf53f9ab7d0747c9dca1cfc
- git.kernel.orghttps://git.kernel.org/stable/c/709e5c088f9c99a5cf2c1d1c6ce58f2cca7ab173
- git.kernel.orghttps://git.kernel.org/stable/c/a3abb54c27b2c393c44362399777ad2f6e1ff17e
- git.kernel.orghttps://git.kernel.org/stable/c/b5df9e06eed3df6a4f5c6f8453013b0cabb927b4
- git.kernel.orghttps://git.kernel.org/stable/c/e58559845021c3bad5e094219378b869157fad53
- git.kernel.orghttps://git.kernel.org/stable/c/f3f3a8eb3f0ba799fae057091d8c67cca12d6fa0
No related CVEs by CWE or product.