Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1336 CNY

100%

CVE-2025-21998— firmware: qcom: uefisecapp: fix efivars registration race

AI Predicted 3.3 Difficulty: Trivial EPSS 0.13% · P3

Possible ATT&CK Techniques 1AI

T1499 · Endpoint Denial of Service

Affected Version Matrix 8

VendorProductVersion RangeStatus
LinuxLinux6612103ec35af6058bb85ab24dae28e119b3c055< c4e37b381a7a243c298a4858fc0a5a74e737c79aaffected
6612103ec35af6058bb85ab24dae28e119b3c055< f15a2b96a0e41c426c63a932d0e63cde7b9784aaaffected
6612103ec35af6058bb85ab24dae28e119b3c055< da8d493a80993972c427002684d0742560f3be4aaffected
6.11affected
< 6.11unaffected
6.12.21≤ 6.12.*unaffected
6.13.9≤ 6.13.*unaffected
6.14≤ *unaffected
Get alerts for future matching vulnerabilitiesLog in to subscribe

I. Basic Information for CVE-2025-21998

Vulnerability Information

Have questions about the vulnerability? See if Shenlong's analysis helps!
View Shenlong Deep Dive ↗

Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.

Vulnerability Title
firmware: qcom: uefisecapp: fix efivars registration race
Source: CVE Program / CVE List V5
Vulnerability Description
In the Linux kernel, the following vulnerability has been resolved: firmware: qcom: uefisecapp: fix efivars registration race Since the conversion to using the TZ allocator, the efivars service is registered before the memory pool has been allocated, something which can lead to a NULL-pointer dereference in case of a racing EFI variable access. Make sure that all resources have been set up before registering the efivars.
Source: CVE Program / CVE List V5
CVSS Information
N/A
Source: CVE Program / CVE List V5
Vulnerability Type
N/A
Source: CVE Program / CVE List V5
Vulnerability Title
Linux kernel 安全漏洞
Source: CNNVD (China National Vulnerability Database)
Vulnerability Description
Linux kernel是美国Linux基金会的开源操作系统Linux所使用的内核。 Linux kernel存在安全漏洞,该漏洞源于efivars注册竞争。
Source: CNNVD (China National Vulnerability Database)
CVSS Information
N/A
Source: CNNVD (China National Vulnerability Database)
Vulnerability Type
N/A
Source: CNNVD (China National Vulnerability Database)

Affected Products

VendorProductAffected VersionsCPESubscribe
LinuxLinux 6612103ec35af6058bb85ab24dae28e119b3c055 ~ c4e37b381a7a243c298a4858fc0a5a74e737c79a -
LinuxLinux 6.11 -

II. Public POCs for CVE-2025-21998

#POC DescriptionSource LinkShenlong Link
AI-Generated POCPremium

No public POC found.

Login to generate AI POC

III. Intelligence Information for CVE-2025-21998

登录查看更多情报信息。

Same Patch Batch · Linux · 2025-04-03 · 13 CVEs total

CVE-2025-220048.6 HIGHnet: atm: fix use after free in lec_send()
CVE-2025-220017.8 HIGHaccel/qaic: Fix integer overflow in qaic_validate_req()
CVE-2025-219997.8 HIGHproc: fix UAF in proc_get_inode()
CVE-2025-22007Bluetooth: Fix error code in chan_alloc_skb_cb()
CVE-2025-22006net: ethernet: ti: am65-cpsw: Fix NAPI registration sequence
CVE-2025-22005ipv6: Fix memleak of nhc_pcpu_rth_output in fib_check_nh_v6_gw().
CVE-2025-22003can: ucan: fix out of bound read in strscpy() source
CVE-2025-22002netfs: Call `invalidate_cache` only if implemented
CVE-2025-22000mm/huge_memory: drop beyond-EOF folios with the right number of refs
CVE-2025-21997xsk: fix an integer overflow in xp_create_and_assign_umem()
CVE-2025-21996drm/radeon: fix uninitialized size issue in radeon_vce_cs_parse()
CVE-2025-21995drm/sched: Fix fence reference count leak

IV. Related Vulnerabilities

V. Comments for CVE-2025-21998

No comments yet


Leave a comment