
Cloud Vulnerability DB
A community-led vulnerabilities database
CVE-2025-21914 is a vulnerability discovered in the Linux kernel's slimbus messaging system, specifically related to transaction ID handling. The vulnerability was disclosed on April 1, 2025, affecting the Linux kernel's slimbus subsystem (NVD).
The vulnerability occurs when slim_do_transfer() returns a timeout error but fails to free the transaction ID (TID) in delayed interrupt scenarios. This results in invalid memory access inside qcom_slim_ngd_rx_msgq_cb() due to the invalid TID. The issue manifests in the call trace through multiple functions including __memcpy_fromio, tasklet_action_common, and run_ksoftirqd, ultimately leading to a kernel panic (NVD).
The vulnerability can lead to a kernel panic with the error message "Oops: Fatal exception in interrupt", causing system instability and potential denial of service conditions (NVD).
The issue has been addressed by implementing a fix that ensures the TID is freed in slim_do_transfer() before returning the timeout error, preventing invalid memory access. This fix has been incorporated into Linux kernel version 6.1.133-1 (Debian Security).
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."