Skip to content
Noroxi
CVE-2025-40110· NVD / CVE Program· CNA Linux

drm/vmwgfx: Fix a null-ptr access in the cursor snooper

In the Linux kernel, the following vulnerability has been resolved: drm/vmwgfx: Fix a null-ptr access in the cursor snooper Check that the resource which is converted to a surface exists before trying to use the cursor snooper on it. vmw_cmd_res_check allows explicit invalid (SVGA3D_INVALID_ID) identifiers because some svga commands accept SVGA3D_INVALID_ID to mean "no surface", unfortunately functions that accept the actual surfaces as objects might (and in case of the cursor snooper, do not) be able to handle null objects. Make sure that we validate not only the identifier (via the vmw_cmd_res_check) but also check that the actual resource exists before trying to do something with it. Fixes unchecked null-ptr reference in the snooping code.

—No exploit Fix available
Published
Nov 11, 2025
Updated
Jun 17, 2026
EPSS
0.2% · 8th percentile
CWE
—
Follow this CVE

Sign in to follow · You’ll be notified if a followed record enters KEV, gets an exploit or is updated.

Report tools

JSON

Action score

0

Monitor

Low priority for now.

CVSS
0 / 40 · —
CISA KEV
0 / 30 · Not listed
EPSS
0 / 30 · 0.2%

Noroxi analysis

No Noroxi analysis for this record yet

We don't hand-write analysis for the hundreds of thousands of vulnerabilities in the database; that wouldn't be honest. For notable, high-impact vulnerabilities our team writes the mechanism, detection and remediation steps.

We use this product, ask for help

Affected systems

—

Versions reported by the vendor

Affected version ranges reported by the assigning authority (Linux). Independent of NVD's CPE analysis and usually ahead of it.

  • Linux Linux

    • 3.8affected
    • c0951b797e7d0f2c6b0df2c0e18185c72d0cf1a1 and later · before 3332212e93d0f6e24f8fe79f975e077c4e68ca39affected · git
    • c0951b797e7d0f2c6b0df2c0e18185c72d0cf1a1 and later · before 86aae7053d2da3fdfde7b2e84d86e4af50490505affected · git
    • c0951b797e7d0f2c6b0df2c0e18185c72d0cf1a1 and later · before af9d88cbf0fce52f465978360542ef679713491faffected · git
    • c0951b797e7d0f2c6b0df2c0e18185c72d0cf1a1 and later · before 299cfb5a7deabdf9ecd30071755672af0aced5ebaffected · git
    • c0951b797e7d0f2c6b0df2c0e18185c72d0cf1a1 and later · before 13c9e4ed125e19484234c960efe5ac9c55119523affected · git
    • c0951b797e7d0f2c6b0df2c0e18185c72d0cf1a1 and later · before b6fca0a07989f361ceda27cb2d09c555d4d4a964affected · git
    • c0951b797e7d0f2c6b0df2c0e18185c72d0cf1a1 and later · before 5ac2c0279053a2c5265d46903432fb26ae2d0da2affected · git
    • before 3.8not affected · semver
    • 5.10.248 and later · up to and including 5.10.*not affected · semver

Package-level exposure

OSV and GitHub Advisory data: ecosystem, package and range. SBOM matching uses this table.

EcosystemPackageAffected rangeFix
Debian:11linuxbefore 5.10.249-15.10.249-1
Debian:12linuxbefore 6.1.162-16.1.162-1
Debian:13linuxbefore 6.12.57-16.12.57-1
Debian:14linuxbefore 6.17.6-16.17.6-1

Other highest-scoring records for the same primary product.

  • CVE-2026-74705udp: fix potential use-after-free in tunnel segmentation
    40Plan
  • CVE-2026-74612veth: fix skb length accounting after XDP frag adjustment
    40Plan
  • CVE-2026-74475vxlan: use neigh_ha_snapshot() in route_shortcircuit()
    40Plan
  • CVE-2026-74309vdpa/octeon_ep: fix IRQ-to-ring mapping in interrupt handler
    40Plan
  • CVE-2026-74280crypto: marvell/octeontx - fix DMA cleanup using wrong loop index
    40Plan
  • CVE-2026-74279crypto: cavium/cpt - fix DMA cleanup using wrong loop index
    40Plan

Remediation

Which version to upgrade to

Fix versions compiled from the vendor, package registries and Microsoft. Verify the vendor's note before upgrading.

Product / packageFixed versionSource
Linux Linux13c9e4ed125e19484234c960efe5ac9c55119523Vendor (CNA)
Linux Linux299cfb5a7deabdf9ecd30071755672af0aced5ebVendor (CNA)
Linux Linux3332212e93d0f6e24f8fe79f975e077c4e68ca39Vendor (CNA)
Linux Linux5ac2c0279053a2c5265d46903432fb26ae2d0da2Vendor (CNA)
Linux Linux86aae7053d2da3fdfde7b2e84d86e4af50490505Vendor (CNA)
Linux Linuxaf9d88cbf0fce52f465978360542ef679713491fVendor (CNA)
Linux Linuxb6fca0a07989f361ceda27cb2d09c555d4d4a964Vendor (CNA)
debian:linux6.1.162-1 · Debian:12Package registry (OSV)

Exploit status

No known public exploit

No public exploit has been observed yet. That doesn't mean you're safe, only that the bar is a little higher.

Research context

For pentesters and researchers: attack profile, score disagreement, timeline, patch commits, credits, variant and chain candidates, bug bounty scope. All derived from existing data; no exploit code.

Timeline

From publication to today: proof of concept, Metasploit module, CISA KEV and fix record. Dates are as reported by the sources.

No dated events beyond publication.

EPSS, last 120 days

FIRST EPSS daily score; only changes of 0.01 or more are recorded (step chart).

Patch and commit links

Commit, PR and diff links among the references. A starting point for patch-diffing and variant hunting; fixes, not exploits.

No commit or PR link among the references.

Finders, reporters and analysts named in the CNA record. Click a name for that researcher’s other records.

No credits in the CNA record.

Variant candidates

Same product, same weakness class, within 18 months. If the patch missed the root cause, the sibling bug is here.

No nightly-computed relations.

Chain candidates

An authentication bypass and a privilege-requiring bug in the same product, published close together: combined they may become an unauthenticated path.

—

Bug bounty scope

No known public program.

Source: bounty-targets-data (public HackerOne, Bugcrowd, Intigriti, YesWeHack listings).

Technical details

No CVSS vector for this record, so attack conditions can't be derived.

Weakness class (CWE)

—

Attack context

MITRE CAPEC attack patterns and ATT&CK techniques for this weakness class (CWE). A starting point for detection rules and threat hunting.

MITRE has no CAPEC/ATT&CK mapping for this CWE.

Change log

  1. Fix✗ → ✓

For records you follow, these changes also arrive as notifications. →

References

All records