We use these services and cookies to improve your user experience. You may opt out if you wish, however, this may limit some features on this site.

Please see our statement on Data Privacy.

Crisp.chat (Helpdesk and Chat)

Ok

THREATINT
PUBLISHED

CVE-2025-21996

drm/radeon: fix uninitialized size issue in radeon_vce_cs_parse()



Description

In the Linux kernel, the following vulnerability has been resolved: drm/radeon: fix uninitialized size issue in radeon_vce_cs_parse() On the off chance that command stream passed from userspace via ioctl() call to radeon_vce_cs_parse() is weirdly crafted and first command to execute is to encode (case 0x03000001), the function in question will attempt to call radeon_vce_cs_reloc() with size argument that has not been properly initialized. Specifically, 'size' will point to 'tmp' variable before the latter had a chance to be assigned any value. Play it safe and init 'tmp' with 0, thus ensuring that radeon_vce_cs_reloc() will catch an early error in cases like these. Found by Linux Verification Center (linuxtesting.org) with static analysis tool SVACE. (cherry picked from commit 2d52de55f9ee7aaee0e09ac443f77855989c6b68)

Reserved 2024-12-29 | Published 2025-04-03 | Updated 2025-05-04 | Assigner Linux

Product status

Default status
unaffected

2fc5703abda201f138faf63bdca743d04dbf4b1a before 0effb378ebce52b897f85cd7f828854b8c7cb636
affected

2fc5703abda201f138faf63bdca743d04dbf4b1a before 5b4d9d20fd455a97920cf158dd19163b879cf65d
affected

2fc5703abda201f138faf63bdca743d04dbf4b1a before 9b2da9c673a0da1359a2151f7ce773e2f77d71a9
affected

2fc5703abda201f138faf63bdca743d04dbf4b1a before 78b07dada3f02f77762d0755a96d35f53b02be69
affected

2fc5703abda201f138faf63bdca743d04dbf4b1a before 3ce08215cad55c10a6eeeb33d3583b6cfffe3ab8
affected

2fc5703abda201f138faf63bdca743d04dbf4b1a before dd1801aa01bba1760357f2a641346ae149686713
affected

2fc5703abda201f138faf63bdca743d04dbf4b1a before f5e049028124f755283f2c07e7a3708361ed1dc8
affected

2fc5703abda201f138faf63bdca743d04dbf4b1a before dd8689b52a24807c2d5ce0a17cb26dc87f75235c
affected

Default status
affected

3.15
affected

Any version before 3.15
unaffected

5.4.292
unaffected

5.10.236
unaffected

5.15.180
unaffected

6.1.132
unaffected

6.6.85
unaffected

6.12.21
unaffected

6.13.9
unaffected

6.14
unaffected

References

git.kernel.org/...c/0effb378ebce52b897f85cd7f828854b8c7cb636

git.kernel.org/...c/5b4d9d20fd455a97920cf158dd19163b879cf65d

git.kernel.org/...c/9b2da9c673a0da1359a2151f7ce773e2f77d71a9

git.kernel.org/...c/78b07dada3f02f77762d0755a96d35f53b02be69

git.kernel.org/...c/3ce08215cad55c10a6eeeb33d3583b6cfffe3ab8

git.kernel.org/...c/dd1801aa01bba1760357f2a641346ae149686713

git.kernel.org/...c/f5e049028124f755283f2c07e7a3708361ed1dc8

git.kernel.org/...c/dd8689b52a24807c2d5ce0a17cb26dc87f75235c

cve.org (CVE-2025-21996)

nvd.nist.gov (CVE-2025-21996)

Download JSON

Share this page
https://cve.threatint.eu/CVE/CVE-2025-21996

Support options

Helpdesk Chat, Email, Knowledgebase