CVE-2025-21697

MEDIUM

Linux Kernel 4.19-6.12.10 - Use-After-Free in DRM V3D Job Completion

Title source: llm
STIX 2.1

Description

In the Linux kernel, the following vulnerability has been resolved: drm/v3d: Ensure job pointer is set to NULL after job completion After a job completes, the corresponding pointer in the device must be set to NULL. Failing to do so triggers a warning when unloading the driver, as it appears the job is still active. To prevent this, assign the job pointer to NULL after completing the job, indicating the job has finished.

Scores

CVSS v3 5.5
EPSS 0.0022
EPSS Percentile 12.9%
Attack Vector LOCAL
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H

CISA SSVC

Vulnrichment
Exploitation none
Automatable no
Technical Impact partial

Details

Status published
Products (24)
linux/Kernel 4.19.0 - 5.4.290linux
linux/Kernel 5.11.0 - 5.15.177linux
linux/Kernel 5.16.0 - 6.1.127linux
linux/Kernel 5.5.0 - 5.10.234linux
linux/Kernel 6.2.0 - 6.6.74linux
linux/Kernel 6.7.0 - 6.12.11linux
Linux/Linux < 4.19
Linux/Linux 14d1d190869685d3a1e8a3f63924e20594557cb2 - 14e0a874488e79086340ba8e2d238cb9596b68a8
Linux/Linux 14d1d190869685d3a1e8a3f63924e20594557cb2 - 1bd6303d08c85072ce40ac01a767ab67195105bd
Linux/Linux 14d1d190869685d3a1e8a3f63924e20594557cb2 - 2a1c88f7ca5c12dff6fa6787492ac910bb9e4407
... and 14 more
Published Feb 12, 2025
Tracked Since Feb 18, 2026