cbcvebase.
CVE-2025-21956
published 2025-04-01

CVE-2025-21956: In the Linux kernel, the following vulnerability has been resolved: drm/amd/display: Assign normalized_pix_clk when color depth = 14 [WHY & HOW] A warning…

PriorityP418medium5.5CVSS 3.1
AVLACLPRLUINSUCNINAH
EPSS
0.21%
10.7th percentile
In the Linux kernel, the following vulnerability has been resolved: drm/amd/display: Assign normalized_pix_clk when color depth = 14 [WHY & HOW] A warning message "WARNING: CPU: 4 PID: 459 at ... /dc_resource.c:3397 calculate_phy_pix_clks+0xef/0x100 [amdgpu]" occurs because the display_color_depth == COLOR_DEPTH_141414 is not handled. This is observed in Radeon RX 6600 XT. It is fixed by assigning pix_clk * (14 * 3) / 24 - same as the rests. Also fixes the indentation in get_norm_pix_clk. (cherry picked from commit 274a87eb389f58eddcbc5659ab0b180b37e92775)

Affected

28 ranges· showing 25
VendorProductVersion rangeFixed in
debianlinux< linux 6.1.133-1 (bookworm)linux 6.1.133-1 (bookworm)
debianlinux-6.1< linux 6.1.133-1 (bookworm)linux 6.1.133-1 (bookworm)
linuxlinux
linuxlinux>= 4562236b3bc0a28aeb6ee93b2d8a849a4c4e1c7c < cca3ab74f90176099b6392e8e894b52b27b3d080cca3ab74f90176099b6392e8e894b52b27b3d080
linuxlinux>= 4562236b3bc0a28aeb6ee93b2d8a849a4c4e1c7c < 0174a2e5770efee9dbd4b58963ed4d939298ff5e0174a2e5770efee9dbd4b58963ed4d939298ff5e
linuxlinux>= 4562236b3bc0a28aeb6ee93b2d8a849a4c4e1c7c < 0c0016712e5dc23ce4a7e673cbebc24a535d8c8a0c0016712e5dc23ce4a7e673cbebc24a535d8c8a
linuxlinux>= 4562236b3bc0a28aeb6ee93b2d8a849a4c4e1c7c < dc831b38680c47d07e425871a9852109183895cfdc831b38680c47d07e425871a9852109183895cf
linuxlinux>= 4562236b3bc0a28aeb6ee93b2d8a849a4c4e1c7c < a8f77e1658d78e4a8bb227a83bcee67de97f7634a8f77e1658d78e4a8bb227a83bcee67de97f7634
linuxlinux>= 4562236b3bc0a28aeb6ee93b2d8a849a4c4e1c7c < 04f90b505ad3a6eed474bbaa03167095fef5203a04f90b505ad3a6eed474bbaa03167095fef5203a
linuxlinux>= 4562236b3bc0a28aeb6ee93b2d8a849a4c4e1c7c < 27df30106690969f7d63604f0d49ed8e9bffa2cb27df30106690969f7d63604f0d49ed8e9bffa2cb
linuxlinux>= 4562236b3bc0a28aeb6ee93b2d8a849a4c4e1c7c < 79e31396fdd7037c503e6add15af7cb00633ea9279e31396fdd7037c503e6add15af7cb00633ea92
linuxlinux_kernel
linuxlinux_kernel>= 0 < 5.10.237-15.10.237-1
linuxlinux_kernel>= 0 < 6.1.133-16.1.133-1
linuxlinux_kernel>= 0 < 6.12.20-16.12.20-1
linuxlinux_kernel>= 0 < 6.12.20-16.12.20-1
linuxlinux_kernel>= 0 < 5.15.0-142.1525.15.0-142.152
linuxlinux_kernel>= 0 < 6.8.0-84.846.8.0-84.84
linuxlinux_kernel>= 0 < 5.4.0-218.2385.4.0-218.238
linuxlinux_kernel>= 4.15 < 5.4.2925.4.292
linuxlinux_kernel>= 5.11 < 5.15.1805.15.180
linuxlinux_kernel>= 5.16 < 6.1.1326.1.132
linuxlinux_kernel>= 5.5 < 5.10.2365.10.236
linuxlinux_kernel>= 6.13 < 6.13.86.13.8
linuxlinux_kernel>= 6.2 < 6.6.846.6.84

CVSS provenance

nvdv3.15.5MEDIUMCVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
osv8.8HIGH
vendor_ubuntu8.8HIGH
vendor_debian5.5MEDIUM
vendor_redhat5.5MEDIUM
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.