CVE-2025-21998 - Apache Firmware Null Pointer Dereference

1 day ago 2
ARTICLE AD BOX
CVE ID : CVE-2025-21998
Published : April 3, 2025, 8:15 a.m. | 40 minutes ago
Description : In the Linux kernel, the following vulnerability has been resolved: firmware: qcom: uefisecapp: fix efivars registration race Since the conversion to using the TZ allocator, the efivars service is registered before the memory pool has been allocated, something which can lead to a NULL-pointer dereference in case of a racing EFI variable access. Make sure that all resources have been set up before registering the efivars.
Severity: 0.0 | NA
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
Read Entire Article