CVE-2025-21940

CVSS 3.1 Score 5.5 of 10 (medium)

Details

Published Apr 1, 2025
Updated: Apr 10, 2025
CWE ID 476

Summary

CVE-2025-21940 is a newly identified vulnerability in the Linux kernel. It involves a NULL pointer dereference in the drm/amdkfd module, specifically in the function kfd_queue_acquire_buffers. This issue was discovered through fuzzing, where an IOCTL call led to a NULL pointer being accessed. If exploited, this vulnerability could result in kernel crashes or potentially more serious consequences. The affected kernel versions are yet to be determined, but a fix has been implemented in commit 049e5bf3c8406f87c3d8e1958e0a16804fa1d530.

Ligh bulbPrevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.

Share