CVE-2025-21996

MEDIUM

Linux Kernel 3.15-6.13.9 - Use of Uninitialized Resource in radeon_vce_cs_parse

Title source: llm
STIX 2.1

Description

In the Linux kernel, the following vulnerability has been resolved: drm/radeon: fix uninitialized size issue in radeon_vce_cs_parse() On the off chance that command stream passed from userspace via ioctl() call to radeon_vce_cs_parse() is weirdly crafted and first command to execute is to encode (case 0x03000001), the function in question will attempt to call radeon_vce_cs_reloc() with size argument that has not been properly initialized. Specifically, 'size' will point to 'tmp' variable before the latter had a chance to be assigned any value. Play it safe and init 'tmp' with 0, thus ensuring that radeon_vce_cs_reloc() will catch an early error in cases like these. Found by Linux Verification Center (linuxtesting.org) with static analysis tool SVACE. (cherry picked from commit 2d52de55f9ee7aaee0e09ac443f77855989c6b68)

Scores

CVSS v3 5.5
EPSS 0.0016
EPSS Percentile 6.0%
Attack Vector LOCAL
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H

CISA SSVC

Vulnrichment
Exploitation none
Automatable no
Technical Impact partial

Details

CWE
CWE-908
Status published
Products (27)
linux/Kernel 3.15.0 - 5.4.292linux
linux/Kernel 5.11.0 - 5.15.180linux
linux/Kernel 5.16.0 - 6.1.132linux
linux/Kernel 5.5.0 - 5.10.236linux
linux/Kernel 6.13.0 - 6.13.9linux
linux/Kernel 6.2.0 - 6.6.85linux
linux/Kernel 6.7.0 - 6.12.21linux
Linux/Linux < 3.15
Linux/Linux 2fc5703abda201f138faf63bdca743d04dbf4b1a - 0effb378ebce52b897f85cd7f828854b8c7cb636
Linux/Linux 2fc5703abda201f138faf63bdca743d04dbf4b1a - 3ce08215cad55c10a6eeeb33d3583b6cfffe3ab8
... and 17 more
Published Apr 03, 2025
Tracked Since Feb 18, 2026