CVE-2025-40148: drm/amd/display: Add NULL pointer checks in dc_stream cursor attribute functions

Published Nov 12, 2025
·
Updated

In the Linux kernel, the following vulnerability has been resolved:

drm/amd/display: Add NULL pointer checks in dcstream cursor attribute functions

The function dcstreamsetcursorattributes() currently dereferences the stream pointer and nested members stream->ctx->dc->currentstate without checking for NULL.

All callers of these functions, such as in dcn30applyidlepoweroptimizations() and amdgpudmplanehandlecursorupdate(), already perform NULL checks before calling these functions.

Fixes below: drivers/gpu/drm/amd/amdgpu/../display/dc/core/dcstream.c:336 dcstreamprogramcursorattributes() error: we previously assumed 'stream' could be null (see line 334)

drivers/gpu/drm/amd/amdgpu/../display/dc/core/dcstream.c 327 bool dcstreamprogramcursorattributes( 328 struct dcstreamstate stream, 329 const struct dccursorattributes attributes) 330 { 331 struct dc dc; 332 bool resetidleoptimizations = false; 333 334 dc = stream ? stream->ctx->dc : NULL; ^^^^^^ The old code assumed stream could be NULL.

335 --> 336 if (dcstreamsetcursorattributes(stream, attributes)) { ^^^^^^ The refactor added an unchecked dereference.

drivers/gpu/drm/amd/amdgpu/../display/dc/core/dcstream.c 313 bool dcstreamsetcursorattributes( 314 struct dcstreamstate stream, 315 const struct dccursorattributes attributes) 316 { 317 bool result = false; 318 319 if (dcstreamcheckcursorattributes(stream, stream->ctx->dc->currentstate, attributes)) { ^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^ Here. This function used to check for if stream as NULL and return false at the start. Probably we should add that back.

Affected Software

1 affected component
Linux Linux kernel (drm/amd/display)

Event History

Nov 12, 2025
CVE Published
via MITRE·10:23 AM
Data Sourced
via MITRE·10:23 AM
Description
Data Sourced
via NVD·11:15 AM
Description
Free Weekly Intel

Don't miss critical vulnerabilities

Join thousands of security professionals who receive our weekly digest of trending CVEs, zero-days, and exploited vulnerabilities.

No spam. Unsubscribe anytime.

Frequently Asked Questions

1

What is the severity of CVE-2025-40148?

CVE-2025-40148 is categorized as a medium severity vulnerability in the Linux kernel.

2

How do I fix CVE-2025-40148?

To fix CVE-2025-40148, you should update to the latest Linux kernel version that includes the patch addressing the NULL pointer checks in the dc_stream cursor attribute functions.

3

What systems are affected by CVE-2025-40148?

CVE-2025-40148 affects various versions of the Linux kernel that utilize the AMD display driver functionality.

4

What are the potential impacts of CVE-2025-40148?

Exploitation of CVE-2025-40148 could lead to a denial of service or unstable system behavior due to null pointer dereferencing.

5

Who is the vendor for CVE-2025-40148?

The vendor for CVE-2025-40148 is Linux, as it pertains to the Linux kernel.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203