VYPR
Medium severity5.5NVD Advisory· Published Mar 7, 2025· Updated Jun 17, 2026

CVE-2025-21843

CVE-2025-21843

Description

In the Linux kernel, the following vulnerability has been resolved:

drm/panthor: avoid garbage value in panthor_ioctl_dev_query()

'priorities_info' is uninitialized, and the uninitialized value is copied to user object when calling PANTHOR_UOBJ_SET(). Using memset to initialize 'priorities_info' to avoid this garbage value problem.

Affected products

6
  • Linux/Kernel5 versions
    cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*+ 4 more
    • cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*range: >=6.13,<6.13.4
    • cpe:2.3:o:linux:linux_kernel:6.14:rc1:*:*:*:*:*:*
    • cpe:2.3:o:linux:linux_kernel:6.14:rc2:*:*:*:*:*:*
    • (no CPE)range: 6.13
    • (no CPE)
  • osv-coords
    Range: >= 6.13.0, < 6.13.4

Patches

Vulnerability mechanics

References

2

News mentions

0

No linked articles in our index yet.