PT-2025-4325 · Linux+3 · Linux Kernel+3

Lucas De Marchi

·

Published

2025-01-09

·

Updated

2025-04-01

·

CVE-2025-21644

CVSS v3.1

5.5

Medium

VectorAV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
Name of the Vulnerable Software and Affected Versions Linux kernel versions prior to 6.13.0-rc4-xe+
Description The issue is related to the Linux kernel's drm/xe component. When the GuC (Graphics Unit Controller) fails to load, the driver becomes unresponsive, but it attempts to perform actions that may not be initialized yet. This can lead to a NULL pointer dereference. The problem can be triggered by forcing a signature failure in the GuC binary. The error messages indicate a failure in the firmware signature verification and a critical error declaring the device as wedged.
Recommendations To resolve the issue, update the Linux kernel to a version that includes the fix for the drm/xe component, specifically the change that moves the xe gt tlb invalidation init() function to be called earlier by xe gt init early(). As a temporary workaround, consider disabling the xe gt tlb invalidation reset() function until a patch is available. Restrict access to the vulnerable drm/xe module to minimize the risk of exploitation. Avoid using the GuC binary in a way that could force a signature failure until the issue is resolved.

Exploit

Fix

NULL Pointer Dereference

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

ALT-PU-2025-3467
BDU:2025-15340
CVE-2025-21644
USN-7379-1
USN-7379-2
USN-7380-1
USN-7381-1
USN-7382-1

Affected Products

Alt Linux
Linuxmint
Linux Kernel
Ubuntu