CVE-2025-40360

Source
https://cve.org/CVERecord?id=CVE-2025-40360
Import Source
https://storage.googleapis.com/osv-test-cve-osv-conversion/osv-output/CVE-2025-40360.json
JSON Data
https://api.test.osv.dev/v1/vulns/CVE-2025-40360
Downstream
Related
Published
2025-12-16T13:39:59.490Z
Modified
2026-03-20T12:43:16.684244Z
Summary
drm/sysfb: Do not dereference NULL pointer in plane reset
Details

In the Linux kernel, the following vulnerability has been resolved:

drm/sysfb: Do not dereference NULL pointer in plane reset

The plane state in __drmgemresetshadowplane() can be NULL. Do not deref that pointer, but forward NULL to the other plane-reset helpers. Clears plane->state to NULL.

v2: - fix typo in commit description (Javier)

Database specific
{
    "cna_assigner": "Linux",
    "osv_generated_from": "https://github.com/CVEProject/cvelistV5/tree/main/cves/2025/40xxx/CVE-2025-40360.json"
}
References

Affected packages

Git / git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git

Affected ranges

Type
GIT
Repo
https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git
Events
Introduced
b715650220311e50448cb499c71084ca8aeeeece
Fixed
6abeff03cb79a2c7f4554a8e8738acd35bb37152
Fixed
c4faf7f417eea8b8d5cc570a1015736f307aa2d5
Fixed
b61ed8005bd3102510fab5015ac6a275c9c5ea16
Fixed
6bdef5648a60e49d4a3b02461ab7ae3776877e77
Fixed
c7d5e69866bbe95c1e4ab4c10a81e0a02d9ea232
Fixed
14e02ed3876f4ab0ed6d3f41972175f8b8df3d70

Database specific

source
"https://storage.googleapis.com/osv-test-cve-osv-conversion/osv-output/CVE-2025-40360.json"

Linux / Kernel

Package

Name
Kernel

Affected ranges

Type
ECOSYSTEM
Events
Introduced
5.15.0
Fixed
5.15.197
Type
ECOSYSTEM
Events
Introduced
5.16.0
Fixed
6.1.159
Type
ECOSYSTEM
Events
Introduced
6.2.0
Fixed
6.6.117
Type
ECOSYSTEM
Events
Introduced
6.7.0
Fixed
6.12.58
Type
ECOSYSTEM
Events
Introduced
6.13.0
Fixed
6.17.8

Database specific

source
"https://storage.googleapis.com/osv-test-cve-osv-conversion/osv-output/CVE-2025-40360.json"