cbcvebase.
CVE-2025-21978
published 2025-04-01

CVE-2025-21978: In the Linux kernel, the following vulnerability has been resolved: drm/hyperv: Fix address space leak when Hyper-V DRM device is removed When a Hyper-V DRM…

PriorityP417medium5.5CVSS 3.1
AVLACLPRLUINSUCNINAH
EPSS
0.18%
7.9th percentile
In the Linux kernel, the following vulnerability has been resolved: drm/hyperv: Fix address space leak when Hyper-V DRM device is removed When a Hyper-V DRM device is probed, the driver allocates MMIO space for the vram, and maps it cacheable. If the device removed, or in the error path for device probing, the MMIO space is released but no unmap is done. Consequently the kernel address space for the mapping is leaked. Fix this by adding iounmap() calls in the device removal path, and in the error path during device probing.

Affected

17 ranges
VendorProductVersion rangeFixed in
debianlinux< linux 6.1.133-1 (bookworm)linux 6.1.133-1 (bookworm)
debianlinux-6.1< linux 6.1.133-1 (bookworm)linux 6.1.133-1 (bookworm)
linuxlinux
linuxlinux>= a0ab5abced550ddeefddb06055ed60779a54eb79 < c40cd24bfb9bfbb315c118ca14ebe6cf52e2dd1ec40cd24bfb9bfbb315c118ca14ebe6cf52e2dd1e
linuxlinux>= a0ab5abced550ddeefddb06055ed60779a54eb79 < ad27b4a51495490b815580d9b935e8eee14d1a9cad27b4a51495490b815580d9b935e8eee14d1a9c
linuxlinux>= a0ab5abced550ddeefddb06055ed60779a54eb79 < 24f1bbfb2be77dad82489c1468bbb14312aab12924f1bbfb2be77dad82489c1468bbb14312aab129
linuxlinux>= a0ab5abced550ddeefddb06055ed60779a54eb79 < 158242b56bf465a73e1edeac0fe828a8acad4499158242b56bf465a73e1edeac0fe828a8acad4499
linuxlinux>= a0ab5abced550ddeefddb06055ed60779a54eb79 < aed709355fd05ef747e1af24a1d5d78cd7feb81eaed709355fd05ef747e1af24a1d5d78cd7feb81e
linuxlinux_kernel
linuxlinux_kernel>= 0 < 6.1.133-16.1.133-1
linuxlinux_kernel>= 0 < 6.12.20-16.12.20-1
linuxlinux_kernel>= 0 < 6.12.20-16.12.20-1
linuxlinux_kernel>= 0 < 6.8.0-84.846.8.0-84.84
linuxlinux_kernel>= 6.0 < 6.1.1326.1.132
linuxlinux_kernel>= 6.13 < 6.13.86.13.8
linuxlinux_kernel>= 6.2 < 6.6.846.6.84
linuxlinux_kernel>= 6.7 < 6.12.206.12.20

CVSS provenance

nvdv3.15.5MEDIUMCVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
osv5.9MEDIUM
vendor_ubuntu5.9MEDIUM
vendor_debian5.5MEDIUM
vendor_redhat5.5MEDIUM
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.