CVE-2025-21940: Linux Kernel
Medium severity, CVSS 5.5. EPSS: 0.2% chance of exploitation in the next 30 days.
In the Linux kernel, the following vulnerability has been resolved: drm/amdkfd: Fix NULL Pointer Dereference in KFD queue Through KFD IOCTL Fuzzing we encountered a NULL pointer derefrence when calling kfd_queue_acquire_buffers. (cherry picked from commit 049e5bf3c8406f87c3d8e1958e0a16804fa1d530)
Affected products
- Linux Linux Kernel: from 6.12, before 6.12.19 (fixed in 6.12.19); from 6.13, before 6.13.7 (fixed in 6.13.7); version 6.14 only
Published 2025-04-01. Last modified 2026-06-17.