CVE-2025-40277

Source
https://cve.org/CVERecord?id=CVE-2025-40277
Import Source
https://storage.googleapis.com/osv-test-cve-osv-conversion/osv-output/CVE-2025-40277.json
JSON Data
https://api.test.osv.dev/v1/vulns/CVE-2025-40277
Downstream
Related
Published
2025-12-06T21:51:00.437Z
Modified
2026-03-20T12:43:15.006878Z
Summary
drm/vmwgfx: Validate command header size against SVGA_CMD_MAX_DATASIZE
Details

In the Linux kernel, the following vulnerability has been resolved:

drm/vmwgfx: Validate command header size against SVGACMDMAX_DATASIZE

This data originates from userspace and is used in buffer offset calculations which could potentially overflow causing an out-of-bounds access.

Database specific
{
    "cna_assigner": "Linux",
    "osv_generated_from": "https://github.com/CVEProject/cvelistV5/tree/main/cves/2025/40xxx/CVE-2025-40277.json"
}
References

Affected packages

Git / git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git

Affected ranges

Type
GIT
Repo
https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git
Events
Introduced
8ce75f8ab9044fe11caaaf2b2c82471023212f9f
Fixed
e58559845021c3bad5e094219378b869157fad53
Fixed
54d458b244893e47bda52ec3943fdfbc8d7d068b
Fixed
709e5c088f9c99a5cf2c1d1c6ce58f2cca7ab173
Fixed
a3abb54c27b2c393c44362399777ad2f6e1ff17e
Fixed
b5df9e06eed3df6a4f5c6f8453013b0cabb927b4
Fixed
5aea2cde03d4247cdcf53f9ab7d0747c9dca1cfc
Fixed
f3f3a8eb3f0ba799fae057091d8c67cca12d6fa0
Fixed
32b415a9dc2c212e809b7ebc2b14bc3fbda2b9af

Database specific

source
"https://storage.googleapis.com/osv-test-cve-osv-conversion/osv-output/CVE-2025-40277.json"

Linux / Kernel

Package

Name
Kernel

Affected ranges

Type
ECOSYSTEM
Events
Introduced
4.3.0
Fixed
5.4.302
Type
ECOSYSTEM
Events
Introduced
5.5.0
Fixed
5.10.247
Type
ECOSYSTEM
Events
Introduced
5.11.0
Fixed
5.15.197
Type
ECOSYSTEM
Events
Introduced
5.16.0
Fixed
6.1.159
Type
ECOSYSTEM
Events
Introduced
6.2.0
Fixed
6.6.117
Type
ECOSYSTEM
Events
Introduced
6.7.0
Fixed
6.12.59
Type
ECOSYSTEM
Events
Introduced
6.13.0
Fixed
6.17.9

Database specific

source
"https://storage.googleapis.com/osv-test-cve-osv-conversion/osv-output/CVE-2025-40277.json"