#VU105158 Resource management error in Linux kernel - CVE-2025-21821


Vulnerability identifier: #VU105158

Vulnerability risk: Low

CVSSv4.0: 4.3 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N/E:U/U:Clear]

CVE-ID: CVE-2025-21821

CWE-ID: CWE-399

Exploitation vector: Local

Exploit availability: No

Vulnerable software:
Linux kernel
Operating systems & Components / Operating system

Vendor: Linux Foundation

Description

The vulnerability allows a local user to perform a denial of service (DoS) attack.

The vulnerability exists due to resource management error within the omap_init_lcd_dma() function in drivers/video/fbdev/omap/lcd_dma.c. A local user can perform a denial of service (DoS) attack.

Mitigation
Install update from vendor's website.

Vulnerable software versions

Linux kernel: All versions


External links
https://git.kernel.org/stable/c/7bbbd311dd503653a2cc86d9226740883051dc92
https://git.kernel.org/stable/c/8392ea100f0b86c234c739c6662f39f0ccc0cefd
https://git.kernel.org/stable/c/aa8e22cbedeb626f2a6bda0aea362353d627cd0a
https://git.kernel.org/stable/c/e4b6b665df815b4841e71b72f06446884e8aad40
https://git.kernel.org/stable/c/fb6a5edb60921887d7d10619fcdcbee9759552cb


Q & A

Can this vulnerability be exploited remotely?

No. This vulnerability can be exploited locally. The attacker should have authentication credentials and successfully authenticate on the system.

Is there known malware, which exploits this vulnerability?

No. We are not aware of malware exploiting this vulnerability.


Latest bulletins with this vulnerability