SB2025040233 - Use-after-free in Linux kernel slimbus driver
Published: April 2, 2025 Updated: May 11, 2025
Breakdown by Severity
- Low
- Medium
- High
- Critical
Description
This security bulletin contains information about 1 security vulnerability.
1) Use-after-free (CVE-ID: CVE-2025-21914)
The vulnerability allows a local user to escalate privileges on the system.
The vulnerability exists due to a use-after-free error within the slim_do_transfer() function in drivers/slimbus/messaging.c. A local user can escalate privileges on the system.
Remediation
Install update from vendor's website.
References
- https://git.kernel.org/stable/c/09d34c4cbc38485c7514069f25348e439555b282
- https://git.kernel.org/stable/c/0c541c8f6da23e0b92f0a6216d899659a7572074
- https://git.kernel.org/stable/c/18ae4cee05c310c299ba75d7477dcf34be67aa16
- https://git.kernel.org/stable/c/6abf3d8bb51cbaf886c3f08109a0462890b10db6
- https://git.kernel.org/stable/c/a32e5198a9134772eb03f7b72a7849094c55bda9
- https://git.kernel.org/stable/c/cec8c0ac173fe5321f03fdb1a09a9cb69bc9a9fe
- https://git.kernel.org/stable/c/dcb0d43ba8eb9517e70b1a0e4b0ae0ab657a0e5a
- https://git.kernel.org/stable/c/faac8e894014e8167471a8e4a5eb35a8fefbb82a
- https://mirrors.edge.kernel.org/pub/linux/kernel/v6.x/ChangeLog-6.6.83