cbcvebase.
CVE-2025-21940
published 2025-04-01

CVE-2025-21940: In the Linux kernel, the following vulnerability has been resolved: drm/amdkfd: Fix NULL Pointer Dereference in KFD queue Through KFD IOCTL Fuzzing we…

PriorityP417medium5.5CVSS 3.1
AVLACLPRLUINSUCNINAH
EPSS
0.19%
9.0th percentile
In the Linux kernel, the following vulnerability has been resolved: drm/amdkfd: Fix NULL Pointer Dereference in KFD queue Through KFD IOCTL Fuzzing we encountered a NULL pointer derefrence when calling kfd_queue_acquire_buffers. (cherry picked from commit 049e5bf3c8406f87c3d8e1958e0a16804fa1d530)

Affected

10 ranges
VendorProductVersion rangeFixed in
debianlinux< linux 6.12.19-1 (forky)linux 6.12.19-1 (forky)
linuxlinux
linuxlinux>= 629568d25fea8ece4f65073f039aeef4e240ab67 < c3cbeafb4e0001d9146df50b470885e02664f3c7c3cbeafb4e0001d9146df50b470885e02664f3c7
linuxlinux>= 629568d25fea8ece4f65073f039aeef4e240ab67 < 33eb8041c5d6c19d46e7bfd23a031844336afd8033eb8041c5d6c19d46e7bfd23a031844336afd80
linuxlinux>= 629568d25fea8ece4f65073f039aeef4e240ab67 < fd617ea3b79d2116d53f76cdb5a3601c0ba6e42ffd617ea3b79d2116d53f76cdb5a3601c0ba6e42f
linuxlinux_kernel
linuxlinux_kernel>= 0 < 6.12.19-16.12.19-1
linuxlinux_kernel>= 0 < 6.12.19-16.12.19-1
linuxlinux_kernel>= 6.12 < 6.12.196.12.19
linuxlinux_kernel>= 6.13 < 6.13.76.13.7

CVSS provenance

nvdv3.15.5MEDIUMCVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
osv5.5MEDIUM
vendor_debian5.5LOW
vendor_redhat5.5MEDIUM
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.