---
id: CVE-2025-21780
title: |-
  In the Linux kernel, the following vulnerability has been resolved:

  drm/amdgpu: avoid buffer overflow attach in smu_sys_set_pp_table()

  It malicious user provides a small pptable through sysfs and then
  a bigger pptable, it may cause buf…
summary: |-
  In the Linux kernel, the following vulnerability has been resolved:

  drm/amdgpu: avoid buffer overflow attach in smu_sys_set_pp_table()

  It malicious user provides a small pptable through sysfs and then
  a bigger pptable, it may cause buf…
severity: high
cvss: 7.8
cvssVector: 'CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H'
cwe:
  - CWE-120
vendor: linux
product: linux_kernel
affected:
  - linux_kernel < 6.1.129
  - 'linux_kernel >= 6.2, < 6.6.79'
  - 'linux_kernel >= 6.7, < 6.12.16'
  - 'linux_kernel >= 6.13, < 6.13.4'
  - linux_kernel = 6.14
patched:
  - linux_kernel 6.13.4
published: '2025-02-27'
updated: '2026-07-14'
source: NVD
sourceUrl: 'https://nvd.nist.gov/vuln/detail/CVE-2025-21780'
references:
  - url: 'https://git.kernel.org/stable/c/1abb2648698bf10783d2236a6b4a7ca5e8021699'
    label: 416baaa9-dc9f-4396-8d5f-8c081fb06d67
  - url: 'https://git.kernel.org/stable/c/231075c5a8ea54f34b7c4794687baa980814e6de'
    label: 416baaa9-dc9f-4396-8d5f-8c081fb06d67
  - url: 'https://git.kernel.org/stable/c/2498d2db1d35e88a2060ea191ae75dce853dd084'
    label: 416baaa9-dc9f-4396-8d5f-8c081fb06d67
  - url: 'https://git.kernel.org/stable/c/3484ea33157bc7334f57e64826ec5a4bf992151a'
    label: 416baaa9-dc9f-4396-8d5f-8c081fb06d67
  - url: 'https://git.kernel.org/stable/c/e43a8b9c4d700ffec819c5043a48769b3e7d9cab'
    label: 416baaa9-dc9f-4396-8d5f-8c081fb06d67
  - url: 'https://lists.debian.org/debian-lts-announce/2025/03/msg00028.html'
    label: af854a3a-2127-422b-91ae-364da2661108
  - url: 'https://cert-portal.siemens.com/productcert/html/ssa-019113.html'
    label: 0b142b55-0307-4c5a-b3c9-f314f3fb7c5e
  - url: >-
      https://security.access.redhat.com/data/csaf/v2/vex/2025/cve-2025-21780.json
  - url: 'https://access.redhat.com/security/cve/CVE-2025-21780'
  - url: 'https://bugzilla.redhat.com/show_bug.cgi?id=2348580'
  - url: 'https://www.cve.org/CVERecord?id=CVE-2025-21780'
  - url: 'https://nvd.nist.gov/vuln/detail/CVE-2025-21780'
  - url: >-
      https://lore.kernel.org/linux-cve-announce/2025022607-CVE-2025-21780-8283@gregkh/T
tags:
  - nvd
  - cve.org
  - csaf
  - vex
  - red-hat
epss: 0.00263
epssPercentile: 0.16108
ingestedAt: '2026-07-14T13:36:55.716Z'
ssvc:
  exploitation: none
  automatable: 'no'
  technicalImpact: total
  timestamp: '2025-10-01T19:30:25.628048Z'
---

## Overview

In the Linux kernel, the following vulnerability has been resolved:

drm/amdgpu: avoid buffer overflow attach in smu_sys_set_pp_table()

It malicious user provides a small pptable through sysfs and then
a bigger pptable, it may cause buffer overflow attack in function
smu_sys_set_pp_table().

## Affected

- `linux_kernel < 6.1.129`
- `linux_kernel >= 6.2, < 6.6.79`
- `linux_kernel >= 6.7, < 6.12.16`
- `linux_kernel >= 6.13, < 6.13.4`
- `linux_kernel = 6.14`

## Remediation

Upgrade past the affected range:

- `linux_kernel 6.13.4`

## Vendor advisories

- **Red Hat VEX** · Important · updated 2026-09-13 · [vex](https://security.access.redhat.com/data/csaf/v2/vex/2025/cve-2025-21780.json)
