cbcvebase.
CVE-2025-21987
published 2025-04-02

CVE-2025-21987: In the Linux kernel, the following vulnerability has been resolved: drm/amdgpu: init return value in amdgpu_ttm_clear_buffer Otherwise an uninitialized value…

PriorityP418medium5.5CVSS 3.1
AVLACLPRLUINSUCNINAH
EPSS
0.18%
7.5th percentile
In the Linux kernel, the following vulnerability has been resolved: drm/amdgpu: init return value in amdgpu_ttm_clear_buffer Otherwise an uninitialized value can be returned if amdgpu_res_cleared returns true for all regions. Possibly closes: https://gitlab.freedesktop.org/drm/amd/-/issues/3812 (cherry picked from commit 7c62aacc3b452f73a1284198c81551035fac6d71)

Affected

10 ranges
VendorProductVersion rangeFixed in
debianlinux< linux 6.12.19-1 (forky)linux 6.12.19-1 (forky)
linuxlinux
linuxlinux>= a68c7eaa7a8ffdec9287ba1561a668d674c20a13 < d2c9625b0ade41f9917875d88173a0cc802b95fcd2c9625b0ade41f9917875d88173a0cc802b95fc
linuxlinux>= a68c7eaa7a8ffdec9287ba1561a668d674c20a13 < 5bd98c2df4a0f2e2dcbdf563feb8d348406377b55bd98c2df4a0f2e2dcbdf563feb8d348406377b5
linuxlinux>= a68c7eaa7a8ffdec9287ba1561a668d674c20a13 < d3c7059b6a8600fc62cd863f1ea203b8675e63e1d3c7059b6a8600fc62cd863f1ea203b8675e63e1
linuxlinux_kernel
linuxlinux_kernel>= 0 < 6.12.19-16.12.19-1
linuxlinux_kernel>= 0 < 6.12.19-16.12.19-1
linuxlinux_kernel>= 6.10 < 6.12.186.12.18
linuxlinux_kernel>= 6.13 < 6.13.66.13.6

CVSS provenance

nvdv3.15.5MEDIUMCVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
osv5.5MEDIUM
vendor_debian5.5LOW
vendor_redhat5.5MEDIUM
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.