Security Advisory

CVE-2025-21842

CVE vulnerability detail — eXtreme Datacenter Security Operations

Published 2025-03-07 09:10:00
Last updated 2026-05-11 21:07:33
Assigner Linux
State PUBLISHED

Description

In the Linux kernel, the following vulnerability has been resolved: amdkfd: properly free gang_ctx_bo when failed to init user queue The destructor of a gtt bo is declared as void amdgpu_amdkfd_free_gtt_mem(struct amdgpu_device *adev, void **mem_obj); Which takes void** as the second parameter. GCC allows passing void* to the function because void* can be implicitly casted to any other types, so it can pass compiling. However, passing this void* parameter into the functions execution process(which expects void** and dereferencing void**) will result in errors.