PT-2025-49077 · Linux+3 · Linux Kernel+3
CVE-2025-40247
·
Published
2025-10-06
·
Updated
2026-08-30
CVSS v2.0
4.6
Medium
| Vector | AV:L/AC:L/Au:S/C:N/I:N/A:C |
Name of the Vulnerable Software and Affected Versions
Linux kernel versions prior to 6.16.0-rc2-00809-g0b6974bb4134-dirty #367
Description
The Linux kernel contains a flaw within the drm/msm subsystem related to the handling of pgtable preallocation. Specifically, the
msm vma job free() function, directly callable from an ioctl, can lead to an error path where prealloc cleanup() is invoked without a prior successful prealloc allocate() call. This can result in a kernel NULL pointer dereference, potentially leading to a system crash. The issue was identified through a reported kernel splat involving a memory abort and a subsequent oops.Recommendations
Update to a version later than 6.16.0-rc2-00809-g0b6974bb4134-dirty #367.
Exploit
Fix
NULL Pointer Dereference
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Debian
Linuxmint
Linux Kernel
Ubuntu