Executive Summary

Informations
Name CVE-2025-21996 First vendor Publication 2025-04-03
Vendor Cve Last vendor Modification 2025-04-14

Security-Database Scoring CVSS v3

Cvss vector : CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
Overall CVSS Score 5.5
Base Score 5.5 Environmental Score 5.5
impact SubScore 3.6 Temporal Score 5.5
Exploitabality Sub Score 1.8
 
Attack Vector Local Attack Complexity Low
Privileges Required Low User Interaction None
Scope Unchanged Confidentiality Impact None
Integrity Impact None Availability Impact High
Calculate full CVSS 3.0 Vectors scores

Security-Database Scoring CVSS v2

Cvss vector :
Cvss Base Score N/A Attack Range N/A
Cvss Impact Score N/A Attack Complexity N/A
Cvss Expoit Score N/A Authentication N/A
Calculate full CVSS 2.0 Vectors scores

Detail

In the Linux kernel, the following vulnerability has been resolved:

drm/radeon: fix uninitialized size issue in radeon_vce_cs_parse()

On the off chance that command stream passed from userspace via ioctl() call to radeon_vce_cs_parse() is weirdly crafted and first command to execute is to encode (case 0x03000001), the function in question will attempt to call radeon_vce_cs_reloc() with size argument that has not been properly initialized. Specifically, 'size' will point to 'tmp' variable before the latter had a chance to be assigned any value.

Play it safe and init 'tmp' with 0, thus ensuring that radeon_vce_cs_reloc() will catch an early error in cases like these.

Found by Linux Verification Center (linuxtesting.org) with static analysis tool SVACE.

(cherry picked from commit 2d52de55f9ee7aaee0e09ac443f77855989c6b68)

Original Source

Url : http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2025-21996

CPE : Common Platform Enumeration

TypeDescriptionCount
Application 8
Os 3718

Sources (Detail)

https://git.kernel.org/stable/c/0effb378ebce52b897f85cd7f828854b8c7cb636
https://git.kernel.org/stable/c/3ce08215cad55c10a6eeeb33d3583b6cfffe3ab8
https://git.kernel.org/stable/c/5b4d9d20fd455a97920cf158dd19163b879cf65d
https://git.kernel.org/stable/c/78b07dada3f02f77762d0755a96d35f53b02be69
https://git.kernel.org/stable/c/9b2da9c673a0da1359a2151f7ce773e2f77d71a9
https://git.kernel.org/stable/c/dd1801aa01bba1760357f2a641346ae149686713
https://git.kernel.org/stable/c/dd8689b52a24807c2d5ce0a17cb26dc87f75235c
https://git.kernel.org/stable/c/f5e049028124f755283f2c07e7a3708361ed1dc8
Source Url

Alert History

If you want to see full details history, please login or register.
0
1
2
3
Date Informations
2025-06-26 02:41:15
  • Multiple Updates
2025-06-25 12:38:20
  • Multiple Updates
2025-06-24 02:45:41
  • Multiple Updates
2025-05-27 02:54:10
  • First insertion