CVE-2025-40354: Linux
High severity, CVSS 7.8. EPSS: 0.2% chance of exploitation in the next 30 days.
In the Linux kernel, the following vulnerability has been resolved: drm/amd/display: increase max link count and fix link->enc NULL pointer access [why] 1.) dc->links[MAX_LINKS] array size smaller than actual requested. max_connector + max_dpia + 4 virtual = 14. increase from 12 to 14. 2.) hw_init() access null LINK_ENC for dpia non display_endpoint. (cherry picked from commit d7f5a61e1b04ed87b008c8d327649d184dc5bb45)
Affected products
- Linux Linux: from 4.15, before 6.12.56 (fixed in 6.12.56); from 6.13, before 6.17.6 (fixed in 6.17.6)
Published 2025-12-16. Last modified 2026-07-30.