CVE-2025-21697: drm/v3d: Ensure job pointer is set to NULL after job completion
drm/v3d: Ensure job pointer is set to NULL after job completion
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
debian/linuxto a version that resolves this vulnerability.Fixed in 5.10.234-1Fixed in 6.1.129-1Fixed in 6.1.135-1Fixed in 6.12.25-1Fixed in 6.12.27-1 - Upgrade
Upgrade
debian/linux-6.1to a version that resolves this vulnerability.Fixed in 6.1.129-1~deb11u1 - Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 5.15.180.1-1 - Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 6.6.76.1-1 - Configuration
Set the corresponding drm/v3d device job pointer to NULL immediately after the job completes, so the driver no longer appears to have an active job when unloading (prevents warnings on unload).
Linux kernel (drm/v3d) job pointer = NULL
Event History
Frequently Asked Questions
What is the severity of CVE-2025-21697?
CVE-2025-21697 has a medium severity rating due to the potential for driver unloading warnings that may affect system stability.
How do I fix CVE-2025-21697?
To fix CVE-2025-21697, ensure that you update to the latest version of the Linux kernel where this vulnerability is addressed.
What is the impact of CVE-2025-21697?
The impact of CVE-2025-21697 primarily affects the ability to unload the driver cleanly, potentially causing system instability.
Which systems are affected by CVE-2025-21697?
CVE-2025-21697 affects systems running specific versions of the Linux kernel with the DRM V3D component.
Is CVE-2025-21697 being actively exploited?
As of now, there are no public reports of CVE-2025-21697 being actively exploited in the wild.