
Cloud Vulnerability DB
A community-led vulnerabilities database
CVE-2025-40334 is a vulnerability in the Linux kernel's drm/amdgpu subsystem caused by missing validation of userq (user queue) buffer virtual addresses and sizes. The flaw allows a userq object's virtual address to be used without verifying it resides within a valid VM mapping. It was published on December 9, 2025, and affects Linux kernel versions from the initial commit up to (but not including) the patched commits. Fixes are included in Linux kernel 6.17.8 and 6.18. The CVSS base score is currently listed as 0.0 (not yet fully scored), and the EPSS score is approximately 0.018% (ENISA EUVD).
The root cause is improper input validation (CWE-20) in the drm/amdgpu driver's user queue handling code. When a userq buffer object is created or submitted, the driver fails to validate that the provided virtual address and size correspond to a valid, resident VM mapping. This means a local attacker with access to the GPU device could supply an arbitrary or out-of-bounds virtual address, potentially causing the kernel to operate on unmapped or unintended memory regions. The fix was applied via two stable kernel commits: 5a577de86c4a (for one affected range) and 9e46b8bb0539 (for another), both targeting the amdgpu userq path (ENISA EUVD, Kernel Patch 1, Kernel Patch 2).
Exploitation of this vulnerability could allow a local user with access to an AMD GPU device to cause kernel memory corruption, a denial of service (system crash), or potentially escalate privileges by manipulating kernel operations on invalid memory regions. The impact is confined to systems running affected Linux kernel versions with AMD GPU hardware and the amdgpu driver loaded. Data integrity and system availability are the primary concerns, with confidentiality impact dependent on the specific memory regions accessed (ENISA EUVD).
There is no public proof-of-concept exploit or evidence of in-the-wild exploitation for CVE-2025-40334 at this time. The EPSS score is very low at approximately 0.018%, reflecting a low probability of near-term exploitation. The vulnerability is not listed in the CISA Known Exploited Vulnerabilities (KEV) catalog. Exploitation requires local access to a system with an AMD GPU and the amdgpu kernel driver loaded (ENISA EUVD).
The vulnerability is fixed in Linux kernel versions 6.17.8 and 6.18. Users should update to these or later kernel versions as soon as possible. As a temporary workaround on systems where upgrading is not immediately feasible, restricting access to AMD GPU devices (e.g., via device permissions or removing untrusted local users' access to /dev/dri/*) can reduce exposure. No vendor-provided configuration-only workaround has been published (ENISA EUVD, Kernel Patch 1, Kernel Patch 2).
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."