LiveActive security incident?Get immediate response
CVE Record

CVE-2025-40069: drm/msm: Fix obj leak in VM_BIND error path

In the Linux kernel, the following vulnerability has been resolved: drm/msm: Fix obj leak in VM_BIND error path If we fail a handle-lookup part way thru, we need to drop the already obtained obj references. Patchwork: https://patchwork.freedesktop.org/patch/669784/

HighCVSS 7.8Not KEV-listedUpdated
Glexia's TakeAutomated analysishigh

Security readout for executives and security teams

Plain-English summary

A Linux MSM graphics-driver error can leave kernel object references unreleased during VM_BIND processing. The supplied record rates the potential confidentiality, integrity, and availability impact as high, but does not explain demonstrated consequences or report attacks. Exploitation requires local access with low privileges.

Executive priority

Treat as high priority on affected multi-user Linux systems using drm/msm and schedule an expedited vendor-supported kernel update. Priority is lower where the driver is absent or untrusted local access is unavailable. The supplied evidence does not justify emergency incident response solely on exploitation concerns.

Technical view

A failed handle lookup during drm/msm VM_BIND can leave references to previously obtained objects unreleased. CVSS 3.1 scores it 7.8: local access, low complexity, low privileges, no user interaction, unchanged scope, and high confidentiality, integrity, and availability impacts. No CWE is assigned.

Likely exposure

Exposure is limited to Linux systems running a listed affected kernel where drm/msm is present and reachable by a low-privileged local user. The bundle identifies 6.17, 6.17.3, and 6.18-related versions, but its range encoding is ambiguous. Verify exact distribution builds against vendor guidance.

Exploitation context

The supplied sources provide no evidence of active exploitation, and the CVE is not listed as KEV. The CVSS vector describes a local, low-complexity attack requiring low privileges and no user interaction. Practical exploitability and the path from the reference leak to high-impact outcomes are not documented.

Researcher notes

The defect is missing reference cleanup after a partial handle-lookup failure in VM_BIND. Two stable-kernel commits are supplied, but the bundle does not map each fix to precise releases or explain exploitability. Treat the CVSS impact claims as risk indicators rather than evidence of demonstrated compromise.

Mitigation direction

  • Update to a vendor-supported kernel release containing the applicable referenced stable fix.
  • Check distribution advisories for exact fixed package versions; the supplied affected-version range is ambiguous.
  • Until patched, reduce untrusted local access on systems using drm/msm.
  • Prioritize multi-user or locally accessible systems with the MSM graphics driver enabled.

Validation and detection

  • Record the running kernel and distribution package version on potentially affected systems.
  • Confirm whether the drm/msm driver is built, loaded, and used.
  • Compare vendor package status with CVE-2025-40069 and the referenced stable commits.
  • After updating, verify the running kernel changed and vendor guidance marks it fixed.
Prepared
Confidence
medium
Sources
4

Generated from the cited source records. This long-tail analysis has not been individually reviewed by a named human.

Potential ATT&CK relevance

Conservative CVE-to-ATT&CK context

These mappings and lookup hints may be relevant to the vulnerability behavior, CWE, affected product, or exposure path. Glexia-inferred context is not an official MITRE, ATT&CK, CWE, or CVE Program mapping.

ATT&CK lookup starting points

Use these exact CWE pages and searches to review the Glexia ATT&CK library from this CVE's weakness and description context.

cve · low confidence lookup

CVE-2025-40069 mapping review

Open the CVE-to-ATT&CK bridge for reviewed, inferred, or future official mappings tied to this CVE.

Open ATT&CK lookup
Vulnerability profileCVE Program record
Severity
High
CVSS
7.8 (3.1)
Known Exploited
No
Published

Vector: CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

Official CVE source material

CNA and ADP enrichment extracted from CVE v5

These fields come from the CVE record and ADP containers, not from Glexia's Take. They preserve time-varying source decisions such as CISA SSVC, KEV status, CVSS metrics, and provider references.

1CVSS vectors
3Timeline events
0ADP providers
3Source links

CVSS vector scores

1 official score

We collect every scored CVSS vector available in the official CNA and ADP containers. When more than one version is present, the table keeps the source vectors side by side instead of collapsing them into the highest score.

ScoreVersionSeverityVectorExploitImpactSource
7.8CVSS 3.1HighCVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H1.85.9Linux

Vulnerability scoring details

Base CVSS 3.1 score

7.8High
CVSS 3.1 vector shape for CVE-2025-40069Attack VectorAttack ComplexityPrivileges RequiredUser InteractionScopeConfidentiality ImpactIntegrity ImpactAvailability Impact

Vector: CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

Attack Vector
NetworkAdjacentLocalPhysical
Attack Complexity
LowHigh
Privileges Required
NoneLowHigh
User Interaction
NoneRequired
Scope
ChangedUnchanged
Confidentiality Impact
HighLowNone
Integrity Impact
HighLowNone
Availability Impact
HighLowNone

Vulnerability timeline

Timeline events are normalized from CVE metadata, CNA source timelines, ADP timelines, and KEV metadata when present.

  1. CVE reservedCVE Program

    The CVE ID was reserved by the assigning CNA.

  2. CVE publishedCVE Program

    The CVE record was published.

  3. CVE updatedCVE Program

    The CVE record metadata indicates this as the latest update time.

Affected products

Products and packages named in the record

VendorProductVersion / packageStatus
LinuxLinux2e6a8a1fe2b262a6dfd0a65041fcd830ee1e7143, 2e6a8a1fe2b262a6dfd0a65041fcd830ee1e7143unaffected
LinuxLinux6.17, 0, 6.17.3, 6.18affected
Weakness

CWE details

No CWE listed

CWE links open Glexia weakness intelligence pages with official CWE context, developer remediation guidance, and related CVE mappings.