Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1336 CNY

100%

CVE-2025-40073— drm/msm: Do not validate SSPP when it is not ready

Quick assessment

Affected
Linux Linux
Exploitation
No confirmed in-the-wild exploitation; assess based on exposure
Recommended action
Check the vendor advisory and references for a fixed version. If immediate upgrade is impossible, restrict exposure and increase monitoring.

Linux kernel是美国Linux基金会的开源操作系统Linux所使用的内核。 Linux kernel存在安全漏洞,该漏洞源于未验证SSPP是否就绪,可能导致空指针取消引用。

AI Predicted 7.8 Difficulty: Moderate EPSS 0.17% · P7

Affected Version Matrix 6

VendorProduct Version RangeStatus
Linux Linux 3ed12a3664b362e3462cca61d41f9a9460c9e260< f1dbb3eedb7db4cad45d2619edb1cce6041f79e3 affected
3ed12a3664b362e3462cca61d41f9a9460c9e260< 6fc616723bb5fd4289d7422fa013da062b44ae55 affected
6.16 affected
< 6.16 unaffected
6.17.3≤ 6.17.* unaffected
6.18≤ * unaffected
Get alerts for future matching vulnerabilities Log in to subscribe

I. Basic Information for CVE-2025-40073

Vulnerability Information

Have questions about the vulnerability? See if Shenlong's analysis helps!
View Shenlong Deep Dive ↗

Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.

Vulnerability Title
drm/msm: Do not validate SSPP when it is not ready
Source: CVE Program / CVE List V5
Vulnerability Description
In the Linux kernel, the following vulnerability has been resolved: drm/msm: Do not validate SSPP when it is not ready Current code will validate current plane and previous plane to confirm they can share a SSPP with multi-rect mode. The SSPP is already allocated for previous plane, while current plane is not associated with any SSPP yet. Null pointer is referenced when validating the SSPP of current plane. Skip SSPP validation for current plane. Unable to handle kernel NULL pointer dereference at virtual address 0000000000000020 Mem abort info: ESR = 0x0000000096000004 EC = 0x25: DABT (current EL), IL = 32 bits SET = 0, FnV = 0 EA = 0, S1PTW = 0 FSC = 0x04: level 0 translation fault Data abort info: ISV = 0, ISS = 0x00000004, ISS2 = 0x00000000 CM = 0, WnR = 0, TnD = 0, TagAccess = 0 GCS = 0, Overlay = 0, DirtyBit = 0, Xs = 0 user pgtable: 4k pages, 48-bit VAs, pgdp=0000000888ac3000 [0000000000000020] pgd=0000000000000000, p4d=0000000000000000 Internal error: Oops: 0000000096000004 [#1] SMP Modules linked in: CPU: 4 UID: 0 PID: 1891 Comm: modetest Tainted: G S 6.15.0-rc2-g3ee3f6e1202e #335 PREEMPT Tainted: [S]=CPU_OUT_OF_SPEC Hardware name: SM8650 EV1 rev1 4slam 2et (DT) pstate: 63400009 (nZCv daif +PAN -UAO +TCO +DIT -SSBS BTYPE=--) pc : dpu_plane_is_multirect_capable+0x68/0x90 lr : dpu_assign_plane_resources+0x288/0x410 sp : ffff800093dcb770 x29: ffff800093dcb770 x28: 0000000000002000 x27: ffff000817c6c000 x26: ffff000806b46368 x25: ffff0008013f6080 x24: ffff00080cbf4800 x23: ffff000810842680 x22: ffff0008013f1080 x21: ffff00080cc86080 x20: ffff000806b463b0 x19: ffff00080cbf5a00 x18: 00000000ffffffff x17: 707a5f657a696c61 x16: 0000000000000003 x15: 0000000000002200 x14: 00000000ffffffff x13: 00aaaaaa00aaaaaa x12: 0000000000000000 x11: ffff000817c6e2b8 x10: 0000000000000000 x9 : ffff80008106a950 x8 : ffff00080cbf48f4 x7 : 0000000000000000 x6 : 0000000000000000 x5 : 0000000000000000 x4 : 0000000000000438 x3 : 0000000000000438 x2 : ffff800082e245e0 x1 : 0000000000000008 x0 : 0000000000000000 Call trace: dpu_plane_is_multirect_capable+0x68/0x90 (P) dpu_crtc_atomic_check+0x5bc/0x650 drm_atomic_helper_check_planes+0x13c/0x220 drm_atomic_helper_check+0x58/0xb8 msm_atomic_check+0xd8/0xf0 drm_atomic_check_only+0x4a8/0x968 drm_atomic_commit+0x50/0xd8 drm_atomic_helper_update_plane+0x140/0x188 __setplane_atomic+0xfc/0x148 drm_mode_setplane+0x164/0x378 drm_ioctl_kernel+0xc0/0x140 drm_ioctl+0x20c/0x500 __arm64_sys_ioctl+0xbc/0xf8 invoke_syscall+0x50/0x120 el0_svc_common.constprop.0+0x48/0xf8 do_el0_svc+0x28/0x40 el0_svc+0x30/0xd0 el0t_64_sync_handler+0x144/0x168 el0t_64_sync+0x198/0x1a0 Code: b9402021 370fffc1 f9401441 3707ff81 (f94010a1) ---[ end trace 0000000000000000 ]--- Patchwork: https://patchwork.freedesktop.org/patch/669224/
Source: CVE Program / CVE List V5
CVSS Information
N/A
Source: CVE Program / CVE List V5
Vulnerability Type
N/A
Source: CVE Program / CVE List V5
Vulnerability Title
Linux kernel 安全漏洞
Source: CNNVD (China National Vulnerability Database)
Vulnerability Description
Linux kernel是美国Linux基金会的开源操作系统Linux所使用的内核。 Linux kernel存在安全漏洞,该漏洞源于未验证SSPP是否就绪,可能导致空指针取消引用。
Source: CNNVD (China National Vulnerability Database)
CVSS Information
N/A
Source: CNNVD (China National Vulnerability Database)
Vulnerability Type
N/A
Source: CNNVD (China National Vulnerability Database)

Affected Products

Vendor Product Affected Versions CPE Subscribe
Linux Linux 3ed12a3664b362e3462cca61d41f9a9460c9e260 ~ f1dbb3eedb7db4cad45d2619edb1cce6041f79e3 -
Linux Linux 6.16 -

II. Public POCs for CVE-2025-40073

# POC Description Source Link Shenlong Link
AI-Generated POC Premium

No public POC found.

Login to generate AI POC

III. Intelligence Information for CVE-2025-40073

登录查看更多情报信息。

Patches & Fixes for CVE-2025-40073 (1)

Same Patch Batch · Linux · 2025-10-28 · 58 CVEs total

CVE-2025-40074 9.8 CRITICAL ipv4: start using dst_dev_rcu()
CVE-2025-40043 8.8 HIGH net: nfc: nci: Add parameter validation for packet data
CVE-2025-40039 8.8 HIGH ksmbd: Fix race condition in RPC handle list access
CVE-2025-40058 8.8 HIGH iommu/vt-d: Disallow dirty tracking if incoherent page walk
CVE-2025-40046 8.6 HIGH io_uring/zcrx: fix overshooting recv limit
CVE-2025-40068 8.4 HIGH fs: ntfs3: Fix integer overflow in run_unpack()
CVE-2025-40075 8.1 HIGH tcp_metrics: use dst_dev_net_rcu()
CVE-2025-40026 7.9 HIGH KVM: x86: Don't (re)check L1 intercepts when completing userspace I/O
CVE-2025-40027 7.8 HIGH net/9p: fix double req put in p9_fd_cancelled
CVE-2025-40051 7.8 HIGH vhost: vringh: Modify the return value check
CVE-2025-40061 7.8 HIGH RDMA/rxe: Fix race in do_task() when draining
CVE-2025-40081 7.8 HIGH perf: arm_spe: Prevent overflow in PERF_IDX2OFF()
CVE-2025-40079 7.8 HIGH riscv, bpf: Sign extend struct ops return values properly
CVE-2025-40028 7.8 HIGH binder: fix double-free in dbitmap
CVE-2025-40041 7.8 HIGH LoongArch: BPF: Sign-extend struct ops return values properly
CVE-2025-40054 7.8 HIGH f2fs: fix UAF issue in f2fs_merge_page_bio()
CVE-2025-40044 7.8 HIGH fs: udf: fix OOB read in lengthAllocDescs handling
CVE-2025-40045 7.8 HIGH ASoC: codecs: wcd937x: set the comp soundwire port correctly
CVE-2025-40025 7.8 HIGH f2fs: fix to do sanity check on node footer for non inode dnode
CVE-2025-40047 7.8 HIGH io_uring/waitid: always prune wait queue entry in io_waitid_wait()

Showing top 20 of 58 CVEs. View all on vendor page &rarr; →

IV. Related Vulnerabilities

V. Comments for CVE-2025-40073

No comments yet


Leave a comment