cbcvebase.
CVE-2025-21998
published 2025-04-03

CVE-2025-21998: In the Linux kernel, the following vulnerability has been resolved: firmware: qcom: uefisecapp: fix efivars registration race Since the conversion to using the…

PriorityP416medium4.7CVSS 3.1
AVLACHPRLUINSUCNINAH
EPSS
0.13%
3.1th percentile
In the Linux kernel, the following vulnerability has been resolved: firmware: qcom: uefisecapp: fix efivars registration race Since the conversion to using the TZ allocator, the efivars service is registered before the memory pool has been allocated, something which can lead to a NULL-pointer dereference in case of a racing EFI variable access. Make sure that all resources have been set up before registering the efivars.

Affected

10 ranges
VendorProductVersion rangeFixed in
debianlinux< linux 6.12.21-1 (forky)linux 6.12.21-1 (forky)
linuxlinux
linuxlinux>= 6612103ec35af6058bb85ab24dae28e119b3c055 < c4e37b381a7a243c298a4858fc0a5a74e737c79ac4e37b381a7a243c298a4858fc0a5a74e737c79a
linuxlinux>= 6612103ec35af6058bb85ab24dae28e119b3c055 < f15a2b96a0e41c426c63a932d0e63cde7b9784aaf15a2b96a0e41c426c63a932d0e63cde7b9784aa
linuxlinux>= 6612103ec35af6058bb85ab24dae28e119b3c055 < da8d493a80993972c427002684d0742560f3be4ada8d493a80993972c427002684d0742560f3be4a
linuxlinux_kernel
linuxlinux_kernel>= 0 < 6.12.21-16.12.21-1
linuxlinux_kernel>= 0 < 6.12.21-16.12.21-1
linuxlinux_kernel>= 6.11 < 6.12.216.12.21
linuxlinux_kernel>= 6.13 < 6.13.96.13.9

CVSS provenance

nvdv3.14.7MEDIUMCVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:N/I:N/A:H
osv5.9MEDIUM
vendor_ubuntu5.9MEDIUM
vendor_debian4.7LOW
vendor_redhat4.7MEDIUM
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.