PT-2025-49077 · Linux+3 · Linux Kernel+3

CVE-2025-40247

·

Published

2025-10-06

·

Updated

2026-08-30

CVSS v2.0

4.6

Medium

VectorAV:L/AC:L/Au:S/C:N/I:N/A:C
Name of the Vulnerable Software and Affected Versions Linux kernel versions prior to 6.16.0-rc2-00809-g0b6974bb4134-dirty #367
Description The Linux kernel contains a flaw within the drm/msm subsystem related to the handling of pgtable preallocation. Specifically, the msm vma job free() function, directly callable from an ioctl, can lead to an error path where prealloc cleanup() is invoked without a prior successful prealloc allocate() call. This can result in a kernel NULL pointer dereference, potentially leading to a system crash. The issue was identified through a reported kernel splat involving a memory abort and a subsequent oops.
Recommendations Update to a version later than 6.16.0-rc2-00809-g0b6974bb4134-dirty #367.

Exploit

Fix

NULL Pointer Dereference

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

BDU:2026-10194
CVE-2025-40247
ECHO-50A7-CBEE-BC23
USN-8094-1
USN-8094-2
USN-8094-3
USN-8094-4
USN-8094-5
USN-8152-1

Affected Products

Debian
Linuxmint
Linux Kernel
Ubuntu