CVE-2025-40069: drm/msm: Fix obj leak in VM_BIND error path
In the Linux kernel, the following vulnerability has been resolved:
drm/msm: Fix obj leak in VM_BIND error path
If we fail a handle-lookup part way thru, we need to drop the already
obtained obj references.
Patchwork: https://patchwork.freedesktop.org/patch/669784/
Security readout for executives and security teams
Plain-English summary
A Linux MSM graphics-driver error can leave kernel object references unreleased during VM_BIND processing. The supplied record rates the potential confidentiality, integrity, and availability impact as high, but does not explain demonstrated consequences or report attacks. Exploitation requires local access with low privileges.
Executive priority
Treat as high priority on affected multi-user Linux systems using drm/msm and schedule an expedited vendor-supported kernel update. Priority is lower where the driver is absent or untrusted local access is unavailable. The supplied evidence does not justify emergency incident response solely on exploitation concerns.
Technical view
A failed handle lookup during drm/msm VM_BIND can leave references to previously obtained objects unreleased. CVSS 3.1 scores it 7.8: local access, low complexity, low privileges, no user interaction, unchanged scope, and high confidentiality, integrity, and availability impacts. No CWE is assigned.
Likely exposure
Exposure is limited to Linux systems running a listed affected kernel where drm/msm is present and reachable by a low-privileged local user. The bundle identifies 6.17, 6.17.3, and 6.18-related versions, but its range encoding is ambiguous. Verify exact distribution builds against vendor guidance.
Exploitation context
The supplied sources provide no evidence of active exploitation, and the CVE is not listed as KEV. The CVSS vector describes a local, low-complexity attack requiring low privileges and no user interaction. Practical exploitability and the path from the reference leak to high-impact outcomes are not documented.
Researcher notes
The defect is missing reference cleanup after a partial handle-lookup failure in VM_BIND. Two stable-kernel commits are supplied, but the bundle does not map each fix to precise releases or explain exploitability. Treat the CVSS impact claims as risk indicators rather than evidence of demonstrated compromise.
Mitigation direction
Update to a vendor-supported kernel release containing the applicable referenced stable fix.
Check distribution advisories for exact fixed package versions; the supplied affected-version range is ambiguous.
Until patched, reduce untrusted local access on systems using drm/msm.
Prioritize multi-user or locally accessible systems with the MSM graphics driver enabled.
Validation and detection
Record the running kernel and distribution package version on potentially affected systems.
Confirm whether the drm/msm driver is built, loaded, and used.
Compare vendor package status with CVE-2025-40069 and the referenced stable commits.
After updating, verify the running kernel changed and vendor guidance marks it fixed.
Generated from the cited source records. This long-tail analysis has not been individually reviewed by a named human.
Potential ATT&CK relevance
Conservative CVE-to-ATT&CK context
These mappings and lookup hints may be relevant to the vulnerability behavior, CWE, affected product, or exposure path. Glexia-inferred context is not an official MITRE, ATT&CK, CWE, or CVE Program mapping.
ATT&CK lookup starting points
Use these exact CWE pages and searches to review the Glexia ATT&CK library from this CVE's weakness and description context.
cve · low confidence lookup
CVE-2025-40069 mapping review
Open the CVE-to-ATT&CK bridge for reviewed, inferred, or future official mappings tied to this CVE.
These fields come from the CVE record and ADP containers, not from Glexia's Take. They preserve time-varying source decisions such as CISA SSVC, KEV status, CVSS metrics, and provider references.
1CVSS vectors
3Timeline events
0ADP providers
3Source links
CVSS vector scores
1 official score
We collect every scored CVSS vector available in the official CNA and ADP containers. When more than one version is present, the table keeps the source vectors side by side instead of collapsing them into the highest score.