CVE-2025-21940: drm/amdkfd: Fix NULL Pointer Dereference in KFD queue
In the Linux kernel, the following vulnerability has been resolved:
drm/amdkfd: Fix NULL Pointer Dereference in KFD queue
Through KFD IOCTL Fuzzing we encountered a NULL pointer derefrence
when calling kfd_queue_acquire_buffers.
(cherry picked from commit 049e5bf3c8406f87c3d8e1958e0a16804fa1d530)
Security readout for executives and security teams
Plain-English summary
CVE-2025-21940 is a Linux kernel bug in AMD KFD queue handling. A local low-privileged user may be able to trigger a NULL pointer dereference and crash affected systems, creating a denial-of-service risk. The sources do not show data theft, privilege escalation, or confirmed active exploitation.
Executive priority
Handle in normal patch cycles for most environments, faster for shared Linux GPU compute systems. The business risk is service disruption, not known compromise, based on the supplied evidence.
Technical view
The flaw is CWE-476 in drm/amdkfd, specifically kfd_queue_acquire_buffers, found through KFD IOCTL fuzzing. The CVSS 3.1 vector is local, low complexity, low privileges, no user interaction, unchanged scope, and high availability impact only. Kernel stable commit references are provided as the resolution evidence.
Likely exposure
Exposure is most relevant to Linux systems running affected kernel builds with AMD KFD/AMDGPU compute functionality available to local users. The supplied version data is incomplete for distro packages, so confirm exposure through vendor kernel advisories and backport status.
Exploitation context
The bundle marks KEV as false and provides no source claiming active exploitation. The described trigger came from IOCTL fuzzing, and the CVSS vector requires local access with low privileges. Treat this primarily as local denial-of-service exposure unless vendor guidance adds new evidence.
Researcher notes
Do not assume remote reachability or privilege escalation from the bundle. Validation should focus on local KFD device exposure, AMD GPU workloads, exact kernel build lineage, and whether the referenced stable commits are present in deployed packages.
Mitigation direction
Update to a vendor kernel containing the referenced stable fixes.
Check distribution advisories for backported fixes to older kernel package versions.
Prioritize GPU compute hosts shared by untrusted or semi-trusted users.
Where feasible, reduce untrusted local access to affected GPU/KFD devices until patched.
Validation and detection
Inventory Linux kernel versions on AMD GPU compute systems.
Check whether vendor packages include the cited stable kernel fixes.
Review access controls for local users with GPU/KFD device access.
Confirm vulnerability scanners map distro backports correctly, not only upstream versions.
Generated from the cited source records. This long-tail analysis has not been individually reviewed by a named human.
Potential ATT&CK relevance
Conservative CVE-to-ATT&CK context
These mappings and lookup hints may be relevant to the vulnerability behavior, CWE, affected product, or exposure path. Glexia-inferred context is not an official MITRE, ATT&CK, CWE, or CVE Program mapping.
ATT&CK lookup starting points
Use these exact CWE pages and searches to review the Glexia ATT&CK library from this CVE's weakness and description context.
cwe · low confidence lookup
CWE-476: Exact CWE lookup
Use the exact CWE identifier as the starting point before reviewing related ATT&CK behavior. Open the exact CWE lookup page first, then review the ATT&CK searches from that MITRE weakness context. This is a Glexia lookup hint, not an official ATT&CK mapping.
These fields come from the CVE record and ADP containers, not from Glexia's Take. They preserve time-varying source decisions such as CISA SSVC, KEV status, CVSS metrics, and provider references.
We collect every scored CVSS vector available in the official CNA and ADP containers. When more than one version is present, the table keeps the source vectors side by side instead of collapsing them into the highest score.
CWE links open Glexia weakness intelligence pages with official CWE context, developer remediation guidance, and related CVE mappings.
CWE-476 · source CWE mapping
NULL Pointer Dereference
NULL Pointer Dereference represents a recurring weakness pattern that can create exploitable paths when design, validation, or implementation controls are missing.