
Cloud Vulnerability DB
A community-led vulnerabilities database
A vulnerability (CVE-2025-38021) was identified in the Linux kernel's AMD display driver component, specifically affecting the drm/amd/display subsystem. The issue was discovered and published to the CVE List on June 18, 2025, involving improper null checks of pipectx->planestate for updatedchubpdpp functionality (NVD, Wiz).
The vulnerability is related to a null pointer dereference issue in the dcn401programpipe function. It shares similarities with a previously addressed issue in commit 6a057072ddd1 that fixed a null pointer dereference in dcn20programpipe. The current vulnerability affects the same function hooked for updatedchubpdpp in dcn401 (NVD).
The vulnerability could lead to a null pointer dereference in the Linux kernel's AMD display driver component, potentially affecting system stability and security (Wiz).
The vulnerability has been resolved through a patch that addresses the null pointer dereference issue. The fix was cherry-picked from commit d8d47f739752227957d8efc0cb894761bfe1d879 (NVD).
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."