SB2025040370 - Memory leak in Linux kernel drm scheduler driver
Published: April 3, 2025 Updated: May 11, 2025
Breakdown by Severity
- Low
- Medium
- High
- Critical
Description
This security bulletin contains information about 1 security vulnerability.
1) Memory leak (CVE-ID: CVE-2025-21995)
The vulnerability allows a local user to perform a denial of service (DoS) attack.
The vulnerability exists due to memory leak within the drm_sched_entity_kill() function in drivers/gpu/drm/scheduler/sched_entity.c. A local user can perform a denial of service (DoS) attack.
Remediation
Install update from vendor's website.
References
- https://git.kernel.org/stable/c/1135a9431160575466ea9ac37ebd756ecbe35fff
- https://git.kernel.org/stable/c/35399c84dcedd6d31448fb9e1336ef52673f2882
- https://git.kernel.org/stable/c/a952f1ab696873be124e31ce5ef964d36bce817f
- https://git.kernel.org/stable/c/c76bd3c99293834de7d1dca5de536616d5655e38
- https://mirrors.edge.kernel.org/pub/linux/kernel/v6.x/ChangeLog-6.6.85