CVE-2025-40334
Linux Debian vulnerability analysis and mitigation

Overview

CVE-2025-40334 is a vulnerability in the Linux kernel's drm/amdgpu subsystem caused by missing validation of userq (user queue) buffer virtual addresses and sizes. The flaw allows a userq object's virtual address to be used without verifying it resides within a valid VM mapping. It was published on December 9, 2025, and affects Linux kernel versions from the initial commit up to (but not including) the patched commits. Fixes are included in Linux kernel 6.17.8 and 6.18. The CVSS base score is currently listed as 0.0 (not yet fully scored), and the EPSS score is approximately 0.018% (ENISA EUVD).

Technical details

The root cause is improper input validation (CWE-20) in the drm/amdgpu driver's user queue handling code. When a userq buffer object is created or submitted, the driver fails to validate that the provided virtual address and size correspond to a valid, resident VM mapping. This means a local attacker with access to the GPU device could supply an arbitrary or out-of-bounds virtual address, potentially causing the kernel to operate on unmapped or unintended memory regions. The fix was applied via two stable kernel commits: 5a577de86c4a (for one affected range) and 9e46b8bb0539 (for another), both targeting the amdgpu userq path (ENISA EUVD, Kernel Patch 1, Kernel Patch 2).

Impact

Exploitation of this vulnerability could allow a local user with access to an AMD GPU device to cause kernel memory corruption, a denial of service (system crash), or potentially escalate privileges by manipulating kernel operations on invalid memory regions. The impact is confined to systems running affected Linux kernel versions with AMD GPU hardware and the amdgpu driver loaded. Data integrity and system availability are the primary concerns, with confidentiality impact dependent on the specific memory regions accessed (ENISA EUVD).

Exploitability

There is no public proof-of-concept exploit or evidence of in-the-wild exploitation for CVE-2025-40334 at this time. The EPSS score is very low at approximately 0.018%, reflecting a low probability of near-term exploitation. The vulnerability is not listed in the CISA Known Exploited Vulnerabilities (KEV) catalog. Exploitation requires local access to a system with an AMD GPU and the amdgpu kernel driver loaded (ENISA EUVD).

Mitigation and workarounds

The vulnerability is fixed in Linux kernel versions 6.17.8 and 6.18. Users should update to these or later kernel versions as soon as possible. As a temporary workaround on systems where upgrading is not immediately feasible, restricting access to AMD GPU devices (e.g., via device permissions or removing untrusted local users' access to /dev/dri/*) can reduce exposure. No vendor-provided configuration-only workaround has been published (ENISA EUVD, Kernel Patch 1, Kernel Patch 2).

Additional resources


SourceThis report was generated using AI

Related Linux Debian vulnerabilities:

CVE ID

Severity

Score

Technologies

Component name

CISA KEV exploit

Has fix

Published date

CVE-2026-74733NONEN/A
  • Linux Debian logoLinux Debian
  • linux
NoYesAug 22, 2026
CVE-2026-74732NONEN/A
  • Linux Kernel logoLinux Kernel
  • kernel-firmware
NoYesAug 22, 2026
CVE-2026-74731NONEN/A
  • Linux Debian logoLinux Debian
  • linux
NoNoAug 22, 2026
CVE-2026-74730NONEN/A
  • Linux Kernel logoLinux Kernel
  • kernel-debug-devel
NoYesAug 22, 2026
CVE-2026-74729NONEN/A
  • Linux Debian logoLinux Debian
  • linux
NoYesAug 22, 2026

Free Vulnerability Assessment

Benchmark your Cloud Security Posture

Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.

Request assessment

Get a personalized demo

Ready to see Wiz in action?

"Best User Experience I have ever seen, provides full visibility to cloud workloads."
David EstlickCISO
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
Adam FletcherChief Security Officer
"We know that if Wiz identifies something as critical, it actually is."
Greg PoniatowskiHead of Threat and Vulnerability Management