CVE-2025-21697 (GCVE-0-2025-21697)
Vulnerability from cvelistv5
Published
2025-02-12 13:27
Modified
2026-08-05 11:53
Summary
In the Linux kernel, the following vulnerability has been resolved: drm/v3d: Ensure job pointer is set to NULL after job completion After a job completes, the corresponding pointer in the device must be set to NULL. Failing to do so triggers a warning when unloading the driver, as it appears the job is still active. To prevent this, assign the job pointer to NULL after completing the job, indicating the job has finished.
Impacted products
Vendor Product Version
Linux Linux Version: 14d1d190869685d3a1e8a3f63924e20594557cb2
Version: 14d1d190869685d3a1e8a3f63924e20594557cb2
Version: 14d1d190869685d3a1e8a3f63924e20594557cb2
Version: 14d1d190869685d3a1e8a3f63924e20594557cb2
Version: 14d1d190869685d3a1e8a3f63924e20594557cb2
Version: 14d1d190869685d3a1e8a3f63924e20594557cb2
Version: 14d1d190869685d3a1e8a3f63924e20594557cb2
Create a notification for this product.
Show details on NVD website


{
  "containers": {
    "adp": [
      {
        "metrics": [
          {
            "cvssV3_1": {
              "attackComplexity": "LOW",
              "attackVector": "LOCAL",
              "availabilityImpact": "HIGH",
              "baseScore": 5.5,
              "baseSeverity": "MEDIUM",
              "confidentialityImpact": "NONE",
              "integrityImpact": "NONE",
              "privilegesRequired": "LOW",
              "scope": "UNCHANGED",
              "userInteraction": "NONE",
              "vectorString": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H",
              "version": "3.1"
            }
          },
          {
            "other": {
              "content": {
                "id": "CVE-2025-21697",
                "options": [
                  {
                    "Exploitation": "none"
                  },
                  {
                    "Automatable": "no"
                  },
                  {
                    "Technical Impact": "partial"
                  }
                ],
                "role": "CISA Coordinator",
                "timestamp": "2025-10-01T19:51:11.490682Z",
                "version": "2.0.3"
              },
              "type": "ssvc"
            }
          }
        ],
        "problemTypes": [
          {
            "descriptions": [
              {
                "description": "CWE-noinfo Not enough information",
                "lang": "en",
                "type": "CWE"
              }
            ]
          }
        ],
        "providerMetadata": {
          "dateUpdated": "2025-10-01T19:57:09.517Z",
          "orgId": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
          "shortName": "CISA-ADP"
        },
        "title": "CISA ADP Vulnrichment"
      },
      {
        "providerMetadata": {
          "dateUpdated": "2025-11-03T20:59:20.493Z",
          "orgId": "af854a3a-2127-422b-91ae-364da2661108",
          "shortName": "CVE"
        },
        "references": [
          {
            "url": "https://lists.debian.org/debian-lts-announce/2025/03/msg00001.html"
          },
          {
            "url": "https://lists.debian.org/debian-lts-announce/2025/03/msg00002.html"
          }
        ],
        "title": "CVE Program Container"
      }
    ],
    "cna": {
      "affected": [
        {
          "defaultStatus": "unaffected",
          "product": "Linux",
          "programFiles": [
            "drivers/gpu/drm/v3d/v3d_irq.c"
          ],
          "repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
          "vendor": "Linux",
          "versions": [
            {
              "lessThan": "1bd6303d08c85072ce40ac01a767ab67195105bd",
              "status": "affected",
              "version": "14d1d190869685d3a1e8a3f63924e20594557cb2",
              "versionType": "git"
            },
            {
              "lessThan": "a34050f70e7955a359874dff1a912a748724a140",
              "status": "affected",
              "version": "14d1d190869685d3a1e8a3f63924e20594557cb2",
              "versionType": "git"
            },
            {
              "lessThan": "14e0a874488e79086340ba8e2d238cb9596b68a8",
              "status": "affected",
              "version": "14d1d190869685d3a1e8a3f63924e20594557cb2",
              "versionType": "git"
            },
            {
              "lessThan": "2a1c88f7ca5c12dff6fa6787492ac910bb9e4407",
              "status": "affected",
              "version": "14d1d190869685d3a1e8a3f63924e20594557cb2",
              "versionType": "git"
            },
            {
              "lessThan": "63195bae1cbf78f1d392b1bc9ae4b03c82d0ebf3",
              "status": "affected",
              "version": "14d1d190869685d3a1e8a3f63924e20594557cb2",
              "versionType": "git"
            },
            {
              "lessThan": "b22467b1ae104073dcb11aa78562a331cd7fb0e0",
              "status": "affected",
              "version": "14d1d190869685d3a1e8a3f63924e20594557cb2",
              "versionType": "git"
            },
            {
              "lessThan": "e4b5ccd392b92300a2b341705cc4805681094e49",
              "status": "affected",
              "version": "14d1d190869685d3a1e8a3f63924e20594557cb2",
              "versionType": "git"
            }
          ]
        },
        {
          "defaultStatus": "affected",
          "product": "Linux",
          "programFiles": [
            "drivers/gpu/drm/v3d/v3d_irq.c"
          ],
          "repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
          "vendor": "Linux",
          "versions": [
            {
              "status": "affected",
              "version": "4.19"
            },
            {
              "lessThan": "4.19",
              "status": "unaffected",
              "version": "0",
              "versionType": "semver"
            },
            {
              "lessThanOrEqual": "5.4.*",
              "status": "unaffected",
              "version": "5.4.290",
              "versionType": "semver"
            },
            {
              "lessThanOrEqual": "5.10.*",
              "status": "unaffected",
              "version": "5.10.234",
              "versionType": "semver"
            },
            {
              "lessThanOrEqual": "5.15.*",
              "status": "unaffected",
              "version": "5.15.177",
              "versionType": "semver"
            },
            {
              "lessThanOrEqual": "6.1.*",
              "status": "unaffected",
              "version": "6.1.127",
              "versionType": "semver"
            },
            {
              "lessThanOrEqual": "6.6.*",
              "status": "unaffected",
              "version": "6.6.74",
              "versionType": "semver"
            },
            {
              "lessThanOrEqual": "6.12.*",
              "status": "unaffected",
              "version": "6.12.11",
              "versionType": "semver"
            },
            {
              "lessThanOrEqual": "*",
              "status": "unaffected",
              "version": "6.13",
              "versionType": "original_commit_for_fix"
            }
          ]
        }
      ],
      "cpeApplicability": [
        {
          "nodes": [
            {
              "cpeMatch": [
                {
                  "criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
                  "versionEndExcluding": "5.4.290",
                  "versionStartIncluding": "4.19",
                  "vulnerable": true
                },
                {
                  "criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
                  "versionEndExcluding": "5.10.234",
                  "versionStartIncluding": "4.19",
                  "vulnerable": true
                },
                {
                  "criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
                  "versionEndExcluding": "5.15.177",
                  "versionStartIncluding": "4.19",
                  "vulnerable": true
                },
                {
                  "criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
                  "versionEndExcluding": "6.1.127",
                  "versionStartIncluding": "4.19",
                  "vulnerable": true
                },
                {
                  "criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
                  "versionEndExcluding": "6.6.74",
                  "versionStartIncluding": "4.19",
                  "vulnerable": true
                },
                {
                  "criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
                  "versionEndExcluding": "6.12.11",
                  "versionStartIncluding": "4.19",
                  "vulnerable": true
                },
                {
                  "criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
                  "versionEndExcluding": "6.13",
                  "versionStartIncluding": "4.19",
                  "vulnerable": true
                }
              ],
              "negate": false,
              "operator": "OR"
            }
          ]
        }
      ],
      "descriptions": [
        {
          "lang": "en",
          "value": "In the Linux kernel, the following vulnerability has been resolved:\n\ndrm/v3d: Ensure job pointer is set to NULL after job completion\n\nAfter a job completes, the corresponding pointer in the device must\nbe set to NULL. Failing to do so triggers a warning when unloading\nthe driver, as it appears the job is still active. To prevent this,\nassign the job pointer to NULL after completing the job, indicating\nthe job has finished."
        }
      ],
      "metrics": [
        {
          "cvssV3_1": {
            "baseScore": 7.8,
            "baseSeverity": "HIGH",
            "vectorString": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H",
            "version": "3.1"
          },
          "scenarios": [
            {
              "lang": "en",
              "value": "AV:L - The vulnerability is reached through the v3d DRM ioctls (`V3D_SUBMIT_CL`/`SUBMIT_CSD`/`SUBMIT_TFU`) on the render node `/dev/dri/renderD128`, which requires local access to the device file. There is no network-facing path into the GPU job submission code.\nAC:L - The attacker controls both sides of the race \u2014 the size/duration of the binner control list that raises the OUTOMEM interrupt and the submission cadence that determines when the bin job completes relative to `v3d_overflow_mem_work()` \u2014 and the driver comment notes the hardware signals OOM before it is fully OOM, making the window occur naturally. Submission can be repeated indefinitely at no cost until the race is won.\nPR:L - An unprivileged local user only needs an open file descriptor on the DRM render node, which is granted to ordinary desktop/graphics users (render/video group) on Raspberry Pi OS and to GPU-passthrough containers; no CAP_SYS_ADMIN or root is required. All relevant ioctls are marked DRM_RENDER_ALLOW, and the upstream crash report shows the path being hit by UID 1000.\nUI:N - The attacker triggers everything itself by submitting GPU jobs from its own process; no victim action, file open, or administrator step is needed.\nS:U - The stale pointer, the freed job object, and the corrupted memory all live in the kernel\u0027s own security authority, and the impact is confined to kernel privilege escalation on the same host. No VM, IOMMU, or sandbox boundary is crossed.\nC:H - The dangling `v3d-\u003ebin_job` is dereferenced after `kfree()`, so `v3d_overflow_mem_work()` and `v3d_irq()` read `-\u003erender`, `-\u003ebase.irq_fence`, and stats fields out of a reclaimed slab object whose contents the attacker can groom, yielding an arbitrary-read primitive and kernel pointer disclosure.\nI:H - `list_add_tail(\u0026bo-\u003eunref_head, \u0026v3d-\u003ebin_job-\u003erender-\u003eunref_list)` writes kernel pointers through a `-\u003erender` value read from freed, attacker-sprayable memory, giving a controlled write primitive; `v3d_job_update_stats()` likewise writes into the freed object. This is a classic use-after-free that can be leveraged into arbitrary write and control-flow hijack.\nA:H - Dereferencing the freed job object reliably oopses or panics the kernel \u2014 the related regression on this same pointer produced \"Kernel panic - not syncing: Oops: Fatal exception in interrupt\" in `v3d_irq()`. Any local user with render-node access can crash the machine on demand."
            }
          ]
        }
      ],
      "providerMetadata": {
        "dateUpdated": "2026-08-05T11:53:40.900Z",
        "orgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
        "shortName": "Linux"
      },
      "references": [
        {
          "url": "https://git.kernel.org/stable/c/1bd6303d08c85072ce40ac01a767ab67195105bd"
        },
        {
          "url": "https://git.kernel.org/stable/c/a34050f70e7955a359874dff1a912a748724a140"
        },
        {
          "url": "https://git.kernel.org/stable/c/14e0a874488e79086340ba8e2d238cb9596b68a8"
        },
        {
          "url": "https://git.kernel.org/stable/c/2a1c88f7ca5c12dff6fa6787492ac910bb9e4407"
        },
        {
          "url": "https://git.kernel.org/stable/c/63195bae1cbf78f1d392b1bc9ae4b03c82d0ebf3"
        },
        {
          "url": "https://git.kernel.org/stable/c/b22467b1ae104073dcb11aa78562a331cd7fb0e0"
        },
        {
          "url": "https://git.kernel.org/stable/c/e4b5ccd392b92300a2b341705cc4805681094e49"
        }
      ],
      "title": "drm/v3d: Ensure job pointer is set to NULL after job completion",
      "x_generator": {
        "engine": "bippy-1.2.0"
      }
    }
  },
  "cveMetadata": {
    "assignerOrgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
    "assignerShortName": "Linux",
    "cveId": "CVE-2025-21697",
    "datePublished": "2025-02-12T13:27:55.488Z",
    "dateReserved": "2024-12-29T08:45:45.748Z",
    "dateUpdated": "2026-08-05T11:53:40.900Z",
    "state": "PUBLISHED"
  },
  "dataType": "CVE_RECORD",
  "dataVersion": "5.2",
  "vulnerability-lookup:meta": {
    "vulnrichment": {
      "containers": "{\"adp\": [{\"title\": \"CVE Program Container\", \"references\": [{\"url\": \"https://lists.debian.org/debian-lts-announce/2025/03/msg00001.html\"}, {\"url\": \"https://lists.debian.org/debian-lts-announce/2025/03/msg00002.html\"}], \"providerMetadata\": {\"orgId\": \"af854a3a-2127-422b-91ae-364da2661108\", \"shortName\": \"CVE\", \"dateUpdated\": \"2025-11-03T20:59:20.493Z\"}}, {\"title\": \"CISA ADP Vulnrichment\", \"metrics\": [{\"cvssV3_1\": {\"scope\": \"UNCHANGED\", \"version\": \"3.1\", \"baseScore\": 5.5, \"attackVector\": \"LOCAL\", \"baseSeverity\": \"MEDIUM\", \"vectorString\": \"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H\", \"integrityImpact\": \"NONE\", \"userInteraction\": \"NONE\", \"attackComplexity\": \"LOW\", \"availabilityImpact\": \"HIGH\", \"privilegesRequired\": \"LOW\", \"confidentialityImpact\": \"NONE\"}}, {\"other\": {\"type\": \"ssvc\", \"content\": {\"id\": \"CVE-2025-21697\", \"role\": \"CISA Coordinator\", \"options\": [{\"Exploitation\": \"none\"}, {\"Automatable\": \"no\"}, {\"Technical Impact\": \"partial\"}], \"version\": \"2.0.3\", \"timestamp\": \"2025-10-01T19:51:11.490682Z\"}}}], \"problemTypes\": [{\"descriptions\": [{\"lang\": \"en\", \"type\": \"CWE\", \"description\": \"CWE-noinfo Not enough information\"}]}], \"providerMetadata\": {\"orgId\": \"134c704f-9b21-4f2e-91b3-4a467353bcc0\", \"shortName\": \"CISA-ADP\", \"dateUpdated\": \"2025-10-01T16:00:33.706Z\"}}], \"cna\": {\"title\": \"drm/v3d: Ensure job pointer is set to NULL after job completion\", \"metrics\": [{\"cvssV3_1\": {\"version\": \"3.1\", \"baseScore\": 7.8, \"baseSeverity\": \"HIGH\", \"vectorString\": \"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H\"}, \"scenarios\": [{\"lang\": \"en\", \"value\": \"AV:L - The vulnerability is reached through the v3d DRM ioctls (`V3D_SUBMIT_CL`/`SUBMIT_CSD`/`SUBMIT_TFU`) on the render node `/dev/dri/renderD128`, which requires local access to the device file. There is no network-facing path into the GPU job submission code.\\nAC:L - The attacker controls both sides of the race \\u2014 the size/duration of the binner control list that raises the OUTOMEM interrupt and the submission cadence that determines when the bin job completes relative to `v3d_overflow_mem_work()` \\u2014 and the driver comment notes the hardware signals OOM before it is fully OOM, making the window occur naturally. Submission can be repeated indefinitely at no cost until the race is won.\\nPR:L - An unprivileged local user only needs an open file descriptor on the DRM render node, which is granted to ordinary desktop/graphics users (render/video group) on Raspberry Pi OS and to GPU-passthrough containers; no CAP_SYS_ADMIN or root is required. All relevant ioctls are marked DRM_RENDER_ALLOW, and the upstream crash report shows the path being hit by UID 1000.\\nUI:N - The attacker triggers everything itself by submitting GPU jobs from its own process; no victim action, file open, or administrator step is needed.\\nS:U - The stale pointer, the freed job object, and the corrupted memory all live in the kernel\u0027s own security authority, and the impact is confined to kernel privilege escalation on the same host. No VM, IOMMU, or sandbox boundary is crossed.\\nC:H - The dangling `v3d-\u003ebin_job` is dereferenced after `kfree()`, so `v3d_overflow_mem_work()` and `v3d_irq()` read `-\u003erender`, `-\u003ebase.irq_fence`, and stats fields out of a reclaimed slab object whose contents the attacker can groom, yielding an arbitrary-read primitive and kernel pointer disclosure.\\nI:H - `list_add_tail(\u0026bo-\u003eunref_head, \u0026v3d-\u003ebin_job-\u003erender-\u003eunref_list)` writes kernel pointers through a `-\u003erender` value read from freed, attacker-sprayable memory, giving a controlled write primitive; `v3d_job_update_stats()` likewise writes into the freed object. This is a classic use-after-free that can be leveraged into arbitrary write and control-flow hijack.\\nA:H - Dereferencing the freed job object reliably oopses or panics the kernel \\u2014 the related regression on this same pointer produced \\\"Kernel panic - not syncing: Oops: Fatal exception in interrupt\\\" in `v3d_irq()`. Any local user with render-node access can crash the machine on demand.\"}]}], \"affected\": [{\"repo\": \"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git\", \"vendor\": \"Linux\", \"product\": \"Linux\", \"versions\": [{\"status\": \"affected\", \"version\": \"14d1d190869685d3a1e8a3f63924e20594557cb2\", \"lessThan\": \"1bd6303d08c85072ce40ac01a767ab67195105bd\", \"versionType\": \"git\"}, {\"status\": \"affected\", \"version\": \"14d1d190869685d3a1e8a3f63924e20594557cb2\", \"lessThan\": \"a34050f70e7955a359874dff1a912a748724a140\", \"versionType\": \"git\"}, {\"status\": \"affected\", \"version\": \"14d1d190869685d3a1e8a3f63924e20594557cb2\", \"lessThan\": \"14e0a874488e79086340ba8e2d238cb9596b68a8\", \"versionType\": \"git\"}, {\"status\": \"affected\", \"version\": \"14d1d190869685d3a1e8a3f63924e20594557cb2\", \"lessThan\": \"2a1c88f7ca5c12dff6fa6787492ac910bb9e4407\", \"versionType\": \"git\"}, {\"status\": \"affected\", \"version\": \"14d1d190869685d3a1e8a3f63924e20594557cb2\", \"lessThan\": \"63195bae1cbf78f1d392b1bc9ae4b03c82d0ebf3\", \"versionType\": \"git\"}, {\"status\": \"affected\", \"version\": \"14d1d190869685d3a1e8a3f63924e20594557cb2\", \"lessThan\": \"b22467b1ae104073dcb11aa78562a331cd7fb0e0\", \"versionType\": \"git\"}, {\"status\": \"affected\", \"version\": \"14d1d190869685d3a1e8a3f63924e20594557cb2\", \"lessThan\": \"e4b5ccd392b92300a2b341705cc4805681094e49\", \"versionType\": \"git\"}], \"programFiles\": [\"drivers/gpu/drm/v3d/v3d_irq.c\"], \"defaultStatus\": \"unaffected\"}, {\"repo\": \"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git\", \"vendor\": \"Linux\", \"product\": \"Linux\", \"versions\": [{\"status\": \"affected\", \"version\": \"4.19\"}, {\"status\": \"unaffected\", \"version\": \"0\", \"lessThan\": \"4.19\", \"versionType\": \"semver\"}, {\"status\": \"unaffected\", \"version\": \"5.4.290\", \"versionType\": \"semver\", \"lessThanOrEqual\": \"5.4.*\"}, {\"status\": \"unaffected\", \"version\": \"5.10.234\", \"versionType\": \"semver\", \"lessThanOrEqual\": \"5.10.*\"}, {\"status\": \"unaffected\", \"version\": \"5.15.177\", \"versionType\": \"semver\", \"lessThanOrEqual\": \"5.15.*\"}, {\"status\": \"unaffected\", \"version\": \"6.1.127\", \"versionType\": \"semver\", \"lessThanOrEqual\": \"6.1.*\"}, {\"status\": \"unaffected\", \"version\": \"6.6.74\", \"versionType\": \"semver\", \"lessThanOrEqual\": \"6.6.*\"}, {\"status\": \"unaffected\", \"version\": \"6.12.11\", \"versionType\": \"semver\", \"lessThanOrEqual\": \"6.12.*\"}, {\"status\": \"unaffected\", \"version\": \"6.13\", \"versionType\": \"original_commit_for_fix\", \"lessThanOrEqual\": \"*\"}], \"programFiles\": [\"drivers/gpu/drm/v3d/v3d_irq.c\"], \"defaultStatus\": \"affected\"}], \"references\": [{\"url\": \"https://git.kernel.org/stable/c/1bd6303d08c85072ce40ac01a767ab67195105bd\"}, {\"url\": \"https://git.kernel.org/stable/c/a34050f70e7955a359874dff1a912a748724a140\"}, {\"url\": \"https://git.kernel.org/stable/c/14e0a874488e79086340ba8e2d238cb9596b68a8\"}, {\"url\": \"https://git.kernel.org/stable/c/2a1c88f7ca5c12dff6fa6787492ac910bb9e4407\"}, {\"url\": \"https://git.kernel.org/stable/c/63195bae1cbf78f1d392b1bc9ae4b03c82d0ebf3\"}, {\"url\": \"https://git.kernel.org/stable/c/b22467b1ae104073dcb11aa78562a331cd7fb0e0\"}, {\"url\": \"https://git.kernel.org/stable/c/e4b5ccd392b92300a2b341705cc4805681094e49\"}], \"x_generator\": {\"engine\": \"bippy-1.2.0\"}, \"descriptions\": [{\"lang\": \"en\", \"value\": \"In the Linux kernel, the following vulnerability has been resolved:\\n\\ndrm/v3d: Ensure job pointer is set to NULL after job completion\\n\\nAfter a job completes, the corresponding pointer in the device must\\nbe set to NULL. Failing to do so triggers a warning when unloading\\nthe driver, as it appears the job is still active. To prevent this,\\nassign the job pointer to NULL after completing the job, indicating\\nthe job has finished.\"}], \"cpeApplicability\": [{\"nodes\": [{\"negate\": false, \"cpeMatch\": [{\"criteria\": \"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*\", \"vulnerable\": true, \"versionEndExcluding\": \"5.4.290\", \"versionStartIncluding\": \"4.19\"}, {\"criteria\": \"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*\", \"vulnerable\": true, \"versionEndExcluding\": \"5.10.234\", \"versionStartIncluding\": \"4.19\"}, {\"criteria\": \"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*\", \"vulnerable\": true, \"versionEndExcluding\": \"5.15.177\", \"versionStartIncluding\": \"4.19\"}, {\"criteria\": \"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*\", \"vulnerable\": true, \"versionEndExcluding\": \"6.1.127\", \"versionStartIncluding\": \"4.19\"}, {\"criteria\": \"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*\", \"vulnerable\": true, \"versionEndExcluding\": \"6.6.74\", \"versionStartIncluding\": \"4.19\"}, {\"criteria\": \"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*\", \"vulnerable\": true, \"versionEndExcluding\": \"6.12.11\", \"versionStartIncluding\": \"4.19\"}, {\"criteria\": \"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*\", \"vulnerable\": true, \"versionEndExcluding\": \"6.13\", \"versionStartIncluding\": \"4.19\"}], \"operator\": \"OR\"}]}], \"providerMetadata\": {\"orgId\": \"416baaa9-dc9f-4396-8d5f-8c081fb06d67\", \"shortName\": \"Linux\", \"dateUpdated\": \"2026-08-05T11:53:40.900Z\"}}}",
      "cveMetadata": "{\"cveId\": \"CVE-2025-21697\", \"state\": \"PUBLISHED\", \"dateUpdated\": \"2026-08-05T11:53:40.900Z\", \"dateReserved\": \"2024-12-29T08:45:45.748Z\", \"assignerOrgId\": \"416baaa9-dc9f-4396-8d5f-8c081fb06d67\", \"datePublished\": \"2025-02-12T13:27:55.488Z\", \"assignerShortName\": \"Linux\"}",
      "dataType": "CVE_RECORD",
      "dataVersion": "5.2"
    }
  }
}


Log in or create an account to share your comment.




Tags
Taxonomy of the tags.


Loading…

Loading…

Loading…

Sightings

Author Source Type Date

Nomenclature

  • Seen: The vulnerability was mentioned, discussed, or seen somewhere by the user.
  • Confirmed: The vulnerability is confirmed from an analyst perspective.
  • Published Proof of Concept: A public proof of concept is available for this vulnerability.
  • Exploited: This vulnerability was exploited and seen by the user reporting the sighting.
  • Patched: This vulnerability was successfully patched by the user reporting the sighting.
  • Not exploited: This vulnerability was not exploited or seen by the user reporting the sighting.
  • Not confirmed: The user expresses doubt about the veracity of the vulnerability.
  • Not patched: This vulnerability was not successfully patched by the user reporting the sighting.


Loading…

Loading…