CVE-2025-40277: drm/vmwgfx: Validate command header size against SVGA_CMD_MAX_DATASIZE
Published Dec 6, 2025
·Updated
drm/vmwgfx: Validate command header size against SVGACMDMAXDATASIZE
Affected Software
3 affected componentsFixes available
Event History
Dec 6, 2025
CVE Published
via MITRE·09:51 PM
Data Sourced
via MITRE·09:51 PM
DescriptionSeverity
Data Sourced
via NVD·10:15 PM
DescriptionSeverity
Dec 8, 2025
Data Sourced
via Microsoft·01:01 AM
DescriptionSeverityWeaknessAffected Software
Updated
via Microsoft·01:01 AM
DescriptionSeverity
Data Sourced
via Red Hat·07:11 AM
DescriptionSeverityAffected Software
Frequently Asked Questions
1
What is the severity of CVE-2025-40277?
CVE-2025-40277 has been classified with a high severity due to potential exploitation risks in the Linux kernel.
2
What does CVE-2025-40277 affect?
CVE-2025-40277 affects the vmwgfx driver in the Linux kernel and the Microsoft azl3 kernel version 6.6.112.1-2.
3
How do I fix CVE-2025-40277?
To fix CVE-2025-40277, update your Linux kernel to a version that includes the patch addressing this vulnerability.
4
What is the impact of CVE-2025-40277?
The impact of CVE-2025-40277 may allow an attacker to manipulate buffer offsets, leading to potential system compromise.
5
Is CVE-2025-40277 being actively exploited?
As of the latest information, there are no confirmed reports of CVE-2025-40277 being actively exploited in the wild.