CVE-2025-21780: drm/amdgpu: avoid buffer overflow attach in smu_sys_set_pp_table()
Published Feb 27, 2025
·Updated
drm/amdgpu: avoid buffer overflow attach in smusyssetpptable()
Affected Software
10 affected componentsFixes available
Linux Kernel
Linux Linux kernel<6.1.129
Linux Linux kernel>=6.2<6.6.79
Linux Linux kernel>=6.7<6.12.16
Linux Linux kernel>=6.13<6.13.4
Linux Linux kernel=6.14-rc1
Linux Linux kernel=6.14-rc2
Microsoft cbl2 kernel 5.15.186.1-1
Microsoft azl3 kernel 6.6.78.1-3
Microsoft azl3 kernel 6.6.79.1-1
Event History
Feb 27, 2025
CVE Published
via MITRE·02:18 AM
Data Sourced
via MITRE·02:18 AM
DescriptionSeverity
Data Sourced
via NVD·03:15 AM
RemedyDescriptionSeverityWeaknessAffected Software
Apr 9, 2025
Data Sourced
via Microsoft·12:00 AM
DescriptionSeverityWeaknessAffected Software
Updated
via Microsoft·07:00 AM
Affected Software
Updated
via Microsoft·07:00 AM
DescriptionSeverity
Frequently Asked Questions
1
What is the severity of CVE-2025-21780?
CVE-2025-21780 is considered a medium severity vulnerability due to its potential for buffer overflow attacks.
2
How do I fix CVE-2025-21780?
To fix CVE-2025-21780, update your Linux kernel to the latest patched version that addresses this vulnerability.
3
What causes the vulnerability in CVE-2025-21780?
CVE-2025-21780 is caused by improper handling of buffer sizes in the smu_sys_set_pp_table() function when processing user-provided data.
4
Who is affected by CVE-2025-21780?
CVE-2025-21780 affects systems running vulnerable versions of the Linux kernel that include the amdgpu driver.
5
What type of attack is associated with CVE-2025-21780?
CVE-2025-21780 is associated with a buffer overflow attack that can be exploited through the sysfs interface.