Executive brief
A vulnerability in the Linux kernel's VMware graphics driver (vmwgfx) could allow a local user to crash the system or potentially gain unauthorized access to data. The issue occurs when the system processes graphics commands from applications without properly checking their size, leading to memory errors. This affects systems running Linux on VMware virtualization platforms.
Technical details
An out-of-bounds access vulnerability exists in the vmwgfx driver within the Linux kernel due to insufficient validation of command header sizes. The `vmw_cmd_check` function in `drivers/gpu/drm/vmwgfx/vmwgfx_execbuf.c` uses size data originating from userspace in buffer offset calculations. Without validating this size against `SVGA_CMD_MAX_DATASIZE`, an attacker can trigger an integer overflow, leading to out-of-bounds memory access. This can result in local privilege escalation or a system crash (DoS). Patches have been released across multiple stable kernel branches.
Affected products
- Linux Linux Kernel 4.3 to 5.4.302, 5.10.247, 5.15.197, 6.1.159, 6.6.64, 6.11.11, 6.12.2
Timeline
- 2025-10-21: disclosed: Initial patch submitted by developer
- 2025-12-06: advisory: CVE-2025-40277 published
- 2025-12-07: patched: Stable kernel updates released
References
- https://git.kernel.org/stable/c/32b415a9dc2c212e809b7ebc2b14bc3fbda2b9af
- https://git.kernel.org/stable/c/54d458b244893e47bda52ec3943fdfbc8d7d068b
- https://git.kernel.org/stable/c/5aea2cde03d4247cdcf53f9ab7d0747c9dca1cfc
- https://git.kernel.org/stable/c/709e5c088f9c99a5cf2c1d1c6ce58f2cca7ab173
- https://git.kernel.org/stable/c/a3abb54c27b2c393c44362399777ad2f6e1ff17e
- https://git.kernel.org/stable/c/b5df9e06eed3df6a4f5c6f8453013b0cabb927b4
- https://git.kernel.org/stable/c/e58559845021c3bad5e094219378b869157fad53