CVE-2025-40354
Last modified
CVE-2025-40354 is a high-severity vulnerability rated 7.8/10 on the CVSS scale. In the Linux kernel, the following vulnerability has been resolved: drm/amd/display: increase max link count and fix link->enc NULL pointer access [why] 1.) dc->links[MAX_LINKS] array size smaller than actual requested. max_connector + max_dpia + 4 virtual = 14. increase from 12 to 14. 2.) hw_init() access null LINK_ENC for dpia non display_endpoint. (cherry picked from commit d7f5a61e1b04ed87b008c8d327649d184dc5bb45). EPSS estimates a 0.17% chance of exploitation in the next 30 days.
Description
In the Linux kernel, the following vulnerability has been resolved: drm/amd/display: increase max link count and fix link->enc NULL pointer access [why] 1.) dc->links[MAX_LINKS] array size smaller than actual requested. max_connector + max_dpia + 4 virtual = 14. increase from 12 to 14. 2.) hw_init() access null LINK_ENC for dpia non display_endpoint. (cherry picked from commit d7f5a61e1b04ed87b008c8d327649d184dc5bb45)
Metrics
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Affected Software
Source: CNA advisory (CVE.org). NVD analysis pending.
| Vendor | Product | Versions |
|---|---|---|
| Linux | Linux | >= 4562236b3bc0a28aeb6ee93b2d8a849a4c4e1c7c, < f28092be4e12b7df9e4f415d25bf0d767bc2d9ed; >= 4562236b3bc0a28aeb6ee93b2d8a849a4c4e1c7c, < a3fc0d36cfb927f8986b83bf5fba47dbedad3c63; >= 4562236b3bc0a28aeb6ee93b2d8a849a4c4e1c7c, < bec947cbe9a65783adb475a5fb47980d7b4f4796 |
| Linux | Linux | 4.15 |
References
Timeline
- Published
- Last Modified
- Status
- Deferred
Frequently Asked Questions
What is CVE-2025-40354?
How severe is CVE-2025-40354?
How do I fix CVE-2025-40354?
How Strix Helps
- How Strix found a critical auth bypass in etcdStrix autonomously discovered a critical authentication bypass in etcd, later designated CVE-2026-33413.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2025
- CVE-2025-40349In the Linux kernel, the following vulnerability has been re…7.8
- CVE-2025-4035A flaw was found in libsoup. When handling cookies, libsoup …4.3
- CVE-2025-40350In the Linux kernel, the following vulnerability has been re…9.8
- CVE-2025-40351In the Linux kernel, the following vulnerability has been re…
- CVE-2025-40352In the Linux kernel, the following vulnerability has been re…
- CVE-2025-40353In the Linux kernel, the following vulnerability has been re…
- CVE-2025-40355In the Linux kernel, the following vulnerability has been re…
- CVE-2025-40356In the Linux kernel, the following vulnerability has been re…7.8
- CVE-2025-40357In the Linux kernel, the following vulnerability has been re…
- CVE-2025-40358In the Linux kernel, the following vulnerability has been re…7.1
- CVE-2025-40359In the Linux kernel, the following vulnerability has been re…
- CVE-2025-4036A vulnerability was found in 201206030 Novel 3.5.0 and class…9.8
Are you affected by CVE-2025-40354?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
