cbcvebase.
CVE-2025-21871
published 2025-03-27

CVE-2025-21871: In the Linux kernel, the following vulnerability has been resolved: tee: optee: Fix supplicant wait loop OP-TEE supplicant is a user-space daemon and it's…

PriorityP419medium5.5CVSS 3.1
AVLACLPRLUINSUCNINAH
EPSS
0.19%
9.0th percentile
In the Linux kernel, the following vulnerability has been resolved: tee: optee: Fix supplicant wait loop OP-TEE supplicant is a user-space daemon and it's possible for it be hung or crashed or killed in the middle of processing an OP-TEE RPC call. It becomes more complicated when there is incorrect shutdown ordering of the supplicant process vs the OP-TEE client application which can eventually lead to system hang-up waiting for the closure of the client application. Allow the client process waiting in kernel for supplicant response to be killed rather than indefinitely waiting in an unkillable state. Also, a normal uninterruptible wait should not have resulted in the hung-task watchdog getting triggered, but the endless loop would. This fixes issues observed during system reboot/shutdown when supplicant got hung for some reason or gets crashed/killed which lead to client getting hung in an unkillable state. It in turn lead to system being in hung up state requiring hard power off/on to recover.

Affected

27 ranges· showing 25
VendorProductVersion rangeFixed in
debianlinux< linux 6.1.133-1 (bookworm)linux 6.1.133-1 (bookworm)
debianlinux-6.1< linux 6.1.133-1 (bookworm)linux 6.1.133-1 (bookworm)
googlechrome_chrome
linuxlinux
linuxlinux>= 4fb0a5eb364d239722e745c02aef0dbd4e0f1ad2 < 3eb4911364c764572e9db4ab900a57689a54e8ce3eb4911364c764572e9db4ab900a57689a54e8ce
linuxlinux>= 4fb0a5eb364d239722e745c02aef0dbd4e0f1ad2 < 0180cf0373f84fff61b16f8c062553a13dd7cfca0180cf0373f84fff61b16f8c062553a13dd7cfca
linuxlinux>= 4fb0a5eb364d239722e745c02aef0dbd4e0f1ad2 < c0a9a948159153be145f9471435695373904ee6dc0a9a948159153be145f9471435695373904ee6d
linuxlinux>= 4fb0a5eb364d239722e745c02aef0dbd4e0f1ad2 < ec18520f5edc20a00c34a8c9fdd6507c355e880fec18520f5edc20a00c34a8c9fdd6507c355e880f
linuxlinux>= 4fb0a5eb364d239722e745c02aef0dbd4e0f1ad2 < d61cc1a435e6894bfb0dd3370c6f765d2d12825dd61cc1a435e6894bfb0dd3370c6f765d2d12825d
linuxlinux>= 4fb0a5eb364d239722e745c02aef0dbd4e0f1ad2 < fd9d2d6124c293e40797a080adf8a9c237efd8b8fd9d2d6124c293e40797a080adf8a9c237efd8b8
linuxlinux>= 4fb0a5eb364d239722e745c02aef0dbd4e0f1ad2 < 21234efe2a8474a6d2d01ea9573319de7858ce4421234efe2a8474a6d2d01ea9573319de7858ce44
linuxlinux>= 4fb0a5eb364d239722e745c02aef0dbd4e0f1ad2 < 70b0d6b0a199c5a3ee6c72f5e61681ed6f75961270b0d6b0a199c5a3ee6c72f5e61681ed6f759612
linuxlinux_kernel
linuxlinux_kernel>= 0 < 5.10.237-15.10.237-1
linuxlinux_kernel>= 0 < 6.1.133-16.1.133-1
linuxlinux_kernel>= 0 < 6.12.17-16.12.17-1
linuxlinux_kernel>= 0 < 6.12.17-16.12.17-1
linuxlinux_kernel>= 0 < 5.4.0-216.2365.4.0-216.236
linuxlinux_kernel>= 0 < 5.15.0-140.1505.15.0-140.150
linuxlinux_kernel>= 0 < 6.8.0-78.786.8.0-78.78
linuxlinux_kernel>= 4.12 < 5.4.2915.4.291
linuxlinux_kernel>= 5.11 < 5.15.1795.15.179
linuxlinux_kernel>= 5.16 < 6.1.1306.1.130
linuxlinux_kernel>= 5.5 < 5.10.2355.10.235
linuxlinux_kernel>= 6.13 < 6.13.56.13.5

CVSS provenance

nvdv3.15.5MEDIUMCVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
osv8.8HIGH
vendor_ubuntu8.8HIGH
vendor_debian5.5MEDIUM
vendor_redhat5.5MEDIUM
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.