Improper locking in Linux kernel - CVE-2025-21911
Published: April 2, 2025 / Updated: May 11, 2025
Vulnerability details
The vulnerability allows a local user to perform a denial of service (DoS) attack.
The vulnerability exists due to improper locking within the pvr_queue_fence_get_driver_name() and pvr_queue_fence_init() functions in drivers/gpu/drm/imagination/pvr_queue.c. A local user can perform a denial of service (DoS) attack.
Affected software
Ubuntu
linux (Ubuntu package)
linux-hwe-6.8 (Ubuntu package)
linux-azure-nvidia (Ubuntu package)
linux-azure (Ubuntu package)
linux-ibm (Ubuntu package)
linux-oracle (Ubuntu package)
linux-oracle-6.8 (Ubuntu package)
linux-aws-6.8 (Ubuntu package)
linux-nvidia (Ubuntu package)
linux-raspi (Ubuntu package)
linux-raspi-realtime (Ubuntu package)
linux-realtime (Ubuntu package)
linux-realtime-6.8 (Ubuntu package)
linux-lowlatency (Ubuntu package)
linux-oem-6.11 (Ubuntu package)
How to mitigate CVE-2025-21911
linux (Ubuntu package) - addressed in versions 6.8.0-84.84, 6.8.0-84.84.1, 6.8.0-84.84.1~22.04.1, 6.8.0-1023.25, 6.8.0-1036.40, 6.8.0-1039.41, 6.8.0-1040.42, 6.11.0-28.28, 6.11.0-28.28~24.04.1, 6.11.0-1011.11, 6.11.0-1014.14, 6.11.0-1015.16, 6.11.0-1016.16, 6.11.0-1016.16~24.04.1, 6.11.0-1017.18
linux-hwe-6.8 (Ubuntu package) - addressed in versions 6.8.0-84.84~22.04.1, 6.8.0-85.85~22.04.1
linux-azure-nvidia (Ubuntu package) - update to 6.8.0-1025.27
linux-azure (Ubuntu package) - addressed in versions 6.8.0-1036.42~22.04.1, 6.8.0-1038.44, 6.11.0-1018.18, 6.11.0-1018.18~24.04.1
linux-ibm (Ubuntu package) - addressed in versions 6.8.0-1037.37, 6.8.0-1037.37~22.04.1
linux-oracle (Ubuntu package) - update to 6.8.0-1037.38
linux-oracle-6.8 (Ubuntu package) - update to 6.8.0-1037.38~22.04.1
linux-aws-6.8 (Ubuntu package) - addressed in versions 6.8.0-1039.41~22.04.1, 6.8.0-1040.42~22.04.1
linux-nvidia (Ubuntu package) - addressed in versions 6.8.0-1039.42, 6.8.0-1039.42.1, 6.8.0-1039.42~22.04.1
linux-raspi (Ubuntu package) - update to 6.8.0-1039.43
linux-raspi-realtime (Ubuntu package) - update to 6.8.0-2031.32
linux-realtime (Ubuntu package) - update to 6.8.1-1034.35
linux-realtime-6.8 (Ubuntu package) - update to 6.8.1-1034.35~22.04.1
linux-lowlatency (Ubuntu package) - addressed in versions 6.11.0-1015.16, 6.11.0-1015.16~24.04.2
linux-oem-6.11 (Ubuntu package) - update to 6.11.0-1024.24
External References
- https://git.kernel.org/stable/c/9bd8b8d34cf4efba18766d64f817c819ed1bbde7
- https://git.kernel.org/stable/c/d993ae7360923efd6ade43a32043459a121c28c1
- https://git.kernel.org/stable/c/df1a1ed5e1bdd9cc13148e0e5549f5ebcf76cf13
- https://mirrors.edge.kernel.org/pub/linux/kernel/v6.x/ChangeLog-6.12.19
- https://mirrors.edge.kernel.org/pub/linux/kernel/v6.x/ChangeLog-6.13.7
- https://mirrors.edge.kernel.org/pub/linux/kernel/v6.x/ChangeLog-6.14
Related Security Bulletins
- Improper locking in Linux kernel drm imagination driver
- Ubuntu update for linux
- Ubuntu update for linux-oem-6.11
- Ubuntu update for linux-lowlatency
- Ubuntu update for linux-azure
- Ubuntu update for linux-nvidia
- Ubuntu update for linux
- Ubuntu update for linux-realtime
- Ubuntu update for linux-aws-6.8
- Ubuntu update for linux-realtime-6.8
- Ubuntu update for linux-ibm
- Ubuntu update for linux-hwe-6.8
- Ubuntu update for linux-raspi
- Ubuntu update for linux-hwe-6.8
- Ubuntu update for linux-raspi-realtime
- Ubuntu update for linux-azure
- Ubuntu update for linux-oracle
- Ubuntu update for linux-azure-nvidia
- Ubuntu update for linux-oracle-6.8