cbcvebase.
CVE-2025-21996
published 2025-04-03

CVE-2025-21996: In the Linux kernel, the following vulnerability has been resolved: drm/radeon: fix uninitialized size issue in radeon_vce_cs_parse() On the off chance that…

PriorityP422medium5.5CVSS 3.1
AVLACLPRLUINSUCNINAH
EPSS
0.19%
8.7th percentile
In the Linux kernel, the following vulnerability has been resolved: drm/radeon: fix uninitialized size issue in radeon_vce_cs_parse() On the off chance that command stream passed from userspace via ioctl() call to radeon_vce_cs_parse() is weirdly crafted and first command to execute is to encode (case 0x03000001), the function in question will attempt to call radeon_vce_cs_reloc() with size argument that has not been properly initialized. Specifically, 'size' will point to 'tmp' variable before the latter had a chance to be assigned any value. Play it safe and init 'tmp' with 0, thus ensuring that radeon_vce_cs_reloc() will catch an early error in cases like these. Found by Linux Verification Center (linuxtesting.org) with static analysis tool SVACE. (cherry picked from commit 2d52de55f9ee7aaee0e09ac443f77855989c6b68)

Affected

32 ranges· showing 25
VendorProductVersion rangeFixed in
debianlinux< linux 6.1.133-1 (bookworm)linux 6.1.133-1 (bookworm)
debianlinux-6.1< linux 6.1.133-1 (bookworm)linux 6.1.133-1 (bookworm)
linuxlinux
linuxlinux>= 2fc5703abda201f138faf63bdca743d04dbf4b1a < 0effb378ebce52b897f85cd7f828854b8c7cb6360effb378ebce52b897f85cd7f828854b8c7cb636
linuxlinux>= 2fc5703abda201f138faf63bdca743d04dbf4b1a < 5b4d9d20fd455a97920cf158dd19163b879cf65d5b4d9d20fd455a97920cf158dd19163b879cf65d
linuxlinux>= 2fc5703abda201f138faf63bdca743d04dbf4b1a < 9b2da9c673a0da1359a2151f7ce773e2f77d71a99b2da9c673a0da1359a2151f7ce773e2f77d71a9
linuxlinux>= 2fc5703abda201f138faf63bdca743d04dbf4b1a < 78b07dada3f02f77762d0755a96d35f53b02be6978b07dada3f02f77762d0755a96d35f53b02be69
linuxlinux>= 2fc5703abda201f138faf63bdca743d04dbf4b1a < 3ce08215cad55c10a6eeeb33d3583b6cfffe3ab83ce08215cad55c10a6eeeb33d3583b6cfffe3ab8
linuxlinux>= 2fc5703abda201f138faf63bdca743d04dbf4b1a < dd1801aa01bba1760357f2a641346ae149686713dd1801aa01bba1760357f2a641346ae149686713
linuxlinux>= 2fc5703abda201f138faf63bdca743d04dbf4b1a < f5e049028124f755283f2c07e7a3708361ed1dc8f5e049028124f755283f2c07e7a3708361ed1dc8
linuxlinux>= 2fc5703abda201f138faf63bdca743d04dbf4b1a < dd8689b52a24807c2d5ce0a17cb26dc87f75235cdd8689b52a24807c2d5ce0a17cb26dc87f75235c
linuxlinux_kernel
linuxlinux_kernel>= 0 < 5.10.237-15.10.237-1
linuxlinux_kernel>= 0 < 6.1.133-16.1.133-1
linuxlinux_kernel>= 0 < 6.12.21-16.12.21-1
linuxlinux_kernel>= 0 < 6.12.21-16.12.21-1
linuxlinux_kernel>= 0 < 5.15.0-142.1525.15.0-142.152
linuxlinux_kernel>= 0 < 6.8.0-84.846.8.0-84.84
linuxlinux_kernel>= 0 < 5.4.0-218.2385.4.0-218.238
linuxlinux_kernel>= 3.15 < 5.4.2925.4.292
linuxlinux_kernel>= 5.11 < 5.15.1805.15.180
linuxlinux_kernel>= 5.16 < 6.1.1326.1.132
linuxlinux_kernel>= 5.5 < 5.10.2365.10.236
linuxlinux_kernel>= 6.13 < 6.13.96.13.9
linuxlinux_kernel>= 6.2 < 6.6.856.6.85

CVSS provenance

nvdv3.15.5MEDIUMCVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
osv8.8HIGH
vendor_ubuntu8.8HIGH
vendor_debian5.5MEDIUM
vendor_msrc5.5MEDIUM
vendor_redhat5.5MEDIUM
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.