CVE-2025-21684

CVSS 3.1 Score 5.5 of 10 (medium)

Details

Published Feb 9, 2025
Updated: Feb 21, 2025
CWE ID 667

Summary

CVE-2025-21684 affects the Linux kernel, specifically the gpio subsystem's xilinx driver. The issue stems from the conversion of gpio_lock to a raw spinlock, leading to irq_chip functions being called in raw spinlock context. This creates a situation where kworker/u17:1/44 tries to acquire a lock held by this thread, resulting in a "Invalid wait context" error. The vulnerability can potentially lead to system instability or denial of service. This issue has been addressed in the kernel by ensuring that both the lock and the raw spinlock are used appropriately.

Ligh bulbPrevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.

Share