CVE-2025-21996

Updated: 2025-04-23 04:27:07.374672

Description:

In the Linux kernel, the following vulnerability has been resolved: drm/radeon: fix uninitialized size issue in radeon_vce_cs_parse() On the off chance that command stream passed from userspace via ioctl() call to radeon_vce_cs_parse() is weirdly crafted and first command to execute is to encode (case 0x03000001), the function in question will attempt to call radeon_vce_cs_reloc() with size argument that has not been properly initialized. Specifically, 'size' will point to 'tmp' variable before the latter had a chance to be assigned any value. Play it safe and init 'tmp' with 0, thus ensuring that radeon_vce_cs_reloc() will catch an early error in cases like these. Found by Linux Verification Center (linuxtesting.org) with static analysis tool SVACE. (cherry picked from commit 2d52de55f9ee7aaee0e09ac443f77855989c6b68)


Links NIST CIRCL RHEL Ubuntu

Severity

Severity Score
CVSS Version 2.x 0
CVSS Version 3.x MEDIUM 5.5

Status

OS name Project name Version Score Severity Status Errata Last updated

Statement

AlmaLinux 9.2 ESU kernel 5.14.0 5.5 MEDIUM Ignored 2025-04-25 03:48:23
AlmaLinux 9.6 ESU kernel 5.14.0 5.5 MEDIUM Ignored 2025-07-05 02:18:02
CentOS 8.4 ELS kernel 4.18.0 5.5 MEDIUM Ignored 2025-04-25 03:48:23
CentOS 8.5 ELS kernel 4.18.0 5.5 MEDIUM Ignored 2025-04-25 03:48:23
CentOS Stream 8 ELS kernel 4.18.0 5.5 MEDIUM Ignored 2025-04-25 03:48:22
Ubuntu 16.04 ELS linux 4.4.0 5.5 MEDIUM Released CLSA-2025:1747430034 2025-05-18 07:45:45
Ubuntu 16.04 ELS linux-hwe 4.15.0 5.5 MEDIUM Released CLSA-2025:1747431461 2025-05-18 07:45:59
Ubuntu 18.04 ELS linux 4.15.0 5.5 MEDIUM Released CLSA-2025:1747430081 2025-05-18 07:45:46
Ubuntu 20.04 ELS linux 5.4.0 5.5 MEDIUM Ignored 2025-06-24 00:41:58