PT-2025-46555 · Linux+4 · Linux Kernel+4

Published

2025-09-26

·

Updated

2026-05-07

·

CVE-2025-40111

CVSS v2.0

5.0

Medium

VectorAV:L/AC:H/Au:S/C:P/I:P/A:C
Name of the Vulnerable Software and Affected Versions Linux kernel (affected versions not specified)
Description The Linux kernel contains a use-after-free issue within the drm/vmwgfx component, specifically in the validation process. Nodes stored in the validation duplicates hashtable, originating from an arena allocator, are not consistently cleared as expected. This occurs because the resource associated with a node may be destroyed prematurely, causing the node to escape proper cleanup during vmw validation drop ht. This can lead to a use-after-free condition.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Exploit

Use After Free

Weakness Enumeration

Related Identifiers

AZL-69956
BDU:2026-02783
CVE-2025-40111
DLA-4379-1
DLA-4404-1
OESA-2026-1275
OESA-2026-1303
OESA-2026-1304
OESA-2026-1305
OPENSUSE-SU-2025:20172-1
SUSE-SU-2025:4393-1
SUSE-SU-2025:4422-1
SUSE-SU-2025:4505-1
SUSE-SU-2025:4516-1
SUSE-SU-2025:4517-1
SUSE-SU-2025:4521-1
SUSE-SU-2026:20012-1
SUSE-SU-2026:20015-1
SUSE-SU-2026:20021-1
SUSE-SU-2026:20039-1
SUSE-SU-2026:20059-1
SUSE-SU-2026:20473-1
SUSE-SU-2026:20496-1
USN-8029-1
USN-8029-2
USN-8029-3
USN-8030-1
USN-8033-1
USN-8033-2
USN-8033-3
USN-8033-4
USN-8033-5
USN-8033-6
USN-8033-7
USN-8033-8
USN-8034-1
USN-8034-2
USN-8048-1
USN-8095-1
USN-8095-2
USN-8095-3
USN-8095-4
USN-8095-5
USN-8100-1
USN-8125-1
USN-8126-1
USN-8141-1
USN-8163-1
USN-8163-2
USN-8165-1
USN-8243-1
USN-8261-1

Affected Products

Debian
Linuxmint
Linux Kernel
Ubuntu
Vmwgfx