PT-2025-14589 · Linux+7 · Linux Kernel+7

Published

2025-03-11

·

Updated

2026-04-20

·

CVE-2025-21996

CVSS v3.1

5.5

Medium

VectorAV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
Name of the Vulnerable Software and Affected Versions Linux kernel (affected versions not specified)
Description The issue arises when a command stream passed from userspace via an ioctl() call to the radeon vce cs parse() function is crafted in a way that the first command to execute is to encode (case 0x03000001). In such cases, the function attempts to call radeon vce cs reloc() with a size argument that has not been properly initialized, as the 'size' will point to the 'tmp' variable before it is assigned any value. To address this, the 'tmp' variable is initialized with 0, ensuring that radeon vce cs reloc() catches an early error in such cases.
Recommendations For the Linux kernel, initialize the 'tmp' variable with 0 in the radeon vce cs parse() function to prevent the size argument from being uninitialized when calling radeon vce cs reloc(). As a temporary workaround, consider restricting access to the radeon vce cs parse() function until a patch is available.

Exploit

Fix

Use of Uninitialized Resource

Access of Uninitialized Pointer

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

ALT-PU-2025-12647
ALT-PU-2025-5437
ALT-PU-2025-5786
ALT-PU-2025-6075
ALT-PU-2025-6082
ALT-PU-2025-6382
ALT-PU-2025-6606
AZL-60252
AZL-60258
BDU:2025-06370
CVE-2025-21996
DLA-4178-1
DLA-4193-1
DSA-5900-1
ECHO-3D84-4068-6898
MGASA-2025-0142
MGASA-2025-0146
OESA-2025-1729
OESA-2025-1730
OESA-2025-1870
OPENSUSE-SU-2025_01614-1
OPENSUSE-SU-2025_01707-1
SUSE-SU-2025:01614-1
SUSE-SU-2025:01707-1
SUSE-SU-2025:01919-1
SUSE-SU-2025:01951-1
SUSE-SU-2025:01964-1
SUSE-SU-2025:01967-1
SUSE-SU-2025:1293-1
SUSE-SU-2025:20192-1
SUSE-SU-2025:20206-1
SUSE-SU-2025:20270-1
SUSE-SU-2025:20283-1
SUSE-SU-2025_01614-1
SUSE-SU-2025_01707-1
SUSE-SU-2025_01951-1
SUSE-SU-2025_01964-1
SUSE-SU-2025_01967-1
SUSE-SU-2025_1293-1
USN-7585-1
USN-7585-2
USN-7585-3
USN-7585-4
USN-7585-5
USN-7585-6
USN-7585-7
USN-7591-1
USN-7591-2
USN-7591-3
USN-7591-4
USN-7591-5
USN-7591-6
USN-7592-1
USN-7593-1
USN-7597-1
USN-7597-2
USN-7598-1
USN-7602-1
USN-7605-1
USN-7605-2
USN-7606-1
USN-7628-1
USN-7640-1
USN-7655-1
USN-7764-1
USN-7764-2
USN-7765-1
USN-7766-1
USN-7767-1
USN-7767-2
USN-7779-1
USN-7790-1
USN-7800-1
USN-7801-1
USN-7801-2
USN-7801-3
USN-7802-1
USN-7809-1

Affected Products

Alt Linux
Astra Linux
Debian
Linuxmint
Linux Kernel
Red Os
Suse
Ubuntu