CVE-2025-40277

Deferred
Published: 06 Dec 2025, 21:51
Last modified:11 May 2026, 21:46

Vulnerability Summary

Overall Risk (default)
minimal
0/100
CVSS Score
No data
EPSS Score
0.08% LOW
0% probability +0.03%
KEV
Not listed
Ransomware
No reports
Public exploits
None found
Dark Web
Not detected

Timeline

06 Dec 2025, 21:51
Published
Vulnerability first disclosed
11 May 2026, 21:46
Last Modified
Vulnerability information updated

Description

In the Linux kernel, the following vulnerability has been resolved: drm/vmwgfx: Validate command header size against SVGA_CMD_MAX_DATASIZE This data originates from userspace and is used in buffer offset calculations which could potentially overflow causing an out-of-bounds access.

EPSS Trends

Current EPSS score: 0.08% Percentile: 24%

Affected Systems

  • linuxlinux

    ≥ 8ce75f8ab9044fe11caaaf2b2c82471023212f9f, < e58559845021c3bad5e094219378b869157fad53 | ≥ 8ce75f8ab9044fe11caaaf2b2c82471023212f9f, < 54d458b244893e47bda52ec3943fdfbc8d7d068b | ≥ 8ce75f8ab9044fe11caaaf2b2c82471023212f9f, < 709e5c088f9c99a5cf2c1d1c6ce58f2cca7ab173 | ≥ 8ce75f8ab9044fe11caaaf2b2c82471023212f9f, < a3abb54c27b2c393c44362399777ad2f6e1ff17e | ≥ 8ce75f8ab9044fe11caaaf2b2c82471023212f9f, < b5df9e06eed3df6a4f5c6f8453013b0cabb927b4 | ≥ 8ce75f8ab9044fe11caaaf2b2c82471023212f9f, < 5aea2cde03d4247cdcf53f9ab7d0747c9dca1cfc | ≥ 8ce75f8ab9044fe11caaaf2b2c82471023212f9f, < f3f3a8eb3f0ba799fae057091d8c67cca12d6fa0 | ≥ 8ce75f8ab9044fe11caaaf2b2c82471023212f9f, < 32b415a9dc2c212e809b7ebc2b14bc3fbda2b9af | 4.3

References (8)