CVE-2025-40148: drm/amd/display: Add NULL pointer checks in dc_stream cursor attribute functions
In the Linux kernel, the following vulnerability has been resolved:
drm/amd/display: Add NULL pointer checks in dcstream cursor attribute functions
The function dcstreamsetcursorattributes() currently dereferences the stream pointer and nested members stream->ctx->dc->currentstate without checking for NULL.
All callers of these functions, such as in dcn30applyidlepoweroptimizations() and amdgpudmplanehandlecursorupdate(), already perform NULL checks before calling these functions.
Fixes below: drivers/gpu/drm/amd/amdgpu/../display/dc/core/dcstream.c:336 dcstreamprogramcursorattributes() error: we previously assumed 'stream' could be null (see line 334)
drivers/gpu/drm/amd/amdgpu/../display/dc/core/dcstream.c 327 bool dcstreamprogramcursorattributes( 328 struct dcstreamstate stream, 329 const struct dccursorattributes attributes) 330 { 331 struct dc dc; 332 bool resetidleoptimizations = false; 333 334 dc = stream ? stream->ctx->dc : NULL; ^^^^^^ The old code assumed stream could be NULL.
335 --> 336 if (dcstreamsetcursorattributes(stream, attributes)) { ^^^^^^ The refactor added an unchecked dereference.
drivers/gpu/drm/amd/amdgpu/../display/dc/core/dcstream.c 313 bool dcstreamsetcursorattributes( 314 struct dcstreamstate stream, 315 const struct dccursorattributes attributes) 316 { 317 bool result = false; 318 319 if (dcstreamcheckcursorattributes(stream, stream->ctx->dc->currentstate, attributes)) { ^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^ Here. This function used to check for if stream as NULL and return false at the start. Probably we should add that back.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2025-40148?
CVE-2025-40148 is categorized as a medium severity vulnerability in the Linux kernel.
How do I fix CVE-2025-40148?
To fix CVE-2025-40148, you should update to the latest Linux kernel version that includes the patch addressing the NULL pointer checks in the dc_stream cursor attribute functions.
What systems are affected by CVE-2025-40148?
CVE-2025-40148 affects various versions of the Linux kernel that utilize the AMD display driver functionality.
What are the potential impacts of CVE-2025-40148?
Exploitation of CVE-2025-40148 could lead to a denial of service or unstable system behavior due to null pointer dereferencing.
Who is the vendor for CVE-2025-40148?
The vendor for CVE-2025-40148 is Linux, as it pertains to the Linux kernel.