We use these services and cookies to improve your user experience. You may opt out if you wish, however, this may limit some features on this site.

Please see our statement on Data Privacy.

Crisp.chat (Helpdesk and Chat)

Ok

THREATINT
PUBLISHED

CVE-2025-21998

firmware: qcom: uefisecapp: fix efivars registration race



Description

In the Linux kernel, the following vulnerability has been resolved: firmware: qcom: uefisecapp: fix efivars registration race Since the conversion to using the TZ allocator, the efivars service is registered before the memory pool has been allocated, something which can lead to a NULL-pointer dereference in case of a racing EFI variable access. Make sure that all resources have been set up before registering the efivars.

Reserved 2024-12-29 | Published 2025-04-03 | Updated 2025-05-04 | Assigner Linux

Product status

Default status
unaffected

6612103ec35af6058bb85ab24dae28e119b3c055 before c4e37b381a7a243c298a4858fc0a5a74e737c79a
affected

6612103ec35af6058bb85ab24dae28e119b3c055 before f15a2b96a0e41c426c63a932d0e63cde7b9784aa
affected

6612103ec35af6058bb85ab24dae28e119b3c055 before da8d493a80993972c427002684d0742560f3be4a
affected

Default status
affected

6.11
affected

Any version before 6.11
unaffected

6.12.21
unaffected

6.13.9
unaffected

6.14
unaffected

References

git.kernel.org/...c/c4e37b381a7a243c298a4858fc0a5a74e737c79a

git.kernel.org/...c/f15a2b96a0e41c426c63a932d0e63cde7b9784aa

git.kernel.org/...c/da8d493a80993972c427002684d0742560f3be4a

cve.org (CVE-2025-21998)

nvd.nist.gov (CVE-2025-21998)

Download JSON

Share this page
https://cve.threatint.eu/CVE/CVE-2025-21998

Support options

Helpdesk Chat, Email, Knowledgebase