PT-2025-49052 · Linux+3 · Linux Kernel+3
CVE-2025-40225
·
Published
2025-10-17
·
Updated
2026-06-30
CVSS v2.0
4.4
Medium
| Vector | AV:L/AC:M/Au:S/C:N/I:N/A:C |
Name of the Vulnerable Software and Affected Versions
Linux kernel (affected versions not specified)
Description
A flaw exists in the Linux kernel's Panthor driver related to GPU virtual address (GPUVA) region unmapping. Specifically, a kernel panic can occur when userspace attempts to partially unmap a GPU virtual region. The issue arises because the driver pre-allocates memory for new drm gpuva structures needed during map/unmap operations, expecting only one new structure for unmapping, but a partial unmap can require two. This leads to a NULL pointer dereference and subsequent kernel panic. The vulnerability is triggered when the
panthor gpuva sm step remap function is called during a partial unmap operation.Recommendations
At the moment, there is no information about a newer version that contains a fix for this vulnerability.
Exploit
NULL Pointer Dereference
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Linuxmint
Linux Kernel
Red Os
Ubuntu