Vulnerability Description
In the Linux kernel, the following vulnerability has been resolved: tty: xilinx_uartps: split sysrq handling lockdep detects the following circular locking dependency: CPU 0 CPU 1 ========================== ============================ cdns_uart_isr() printk() uart_port_lock(port) console_lock() cdns_uart_console_write() if (!port->sysrq) uart_port_lock(port) uart_handle_break() port->sysrq = ... uart_handle_sysrq_char() printk() console_lock() The fixed commit attempts to avoid this situation by only taking the port lock in cdns_uart_console_write if port->sysrq unset. However, if (as shown above) cdns_uart_console_write runs before port->sysrq is set, then it will try to take the port lock anyway. This may result in a deadlock. Fix this by splitting sysrq handling into two parts. We use the prepare helper under the port lock and defer handling until we release the lock.
CVSS Score
MEDIUM
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Linux | Linux Kernel | >= 4.6, < 6.1.129 |
Related Weaknesses (CWE)
References
- https://git.kernel.org/stable/c/4410dba9807a17a93f649a9f5870ceaf30a675a3Patch
- https://git.kernel.org/stable/c/8ea0e7b3d7b8f2f0fc9db491ff22a0abe120801cPatch
- https://git.kernel.org/stable/c/9b88a7c4584ba67267a051069b8abe44fc9595b2Patch
- https://git.kernel.org/stable/c/b06f388994500297bb91be60ffaf6825ecfd2afePatch
- https://git.kernel.org/stable/c/de5bd24197bd9ee37ec1e379a3d882bbd15c5065Patch
- https://git.kernel.org/stable/c/e22a97700901ba5e8bf8db68056a0d50f9440cae
- https://lists.debian.org/debian-lts-announce/2025/03/msg00028.html
FAQ
What is CVE-2025-21820?
CVE-2025-21820 is a vulnerability with a CVSS score of 5.5 (MEDIUM). In the Linux kernel, the following vulnerability has been resolved: tty: xilinx_uartps: split sysrq handling lockdep detects the following circular locking dependency: CPU 0 CP...
How severe is CVE-2025-21820?
CVE-2025-21820 has been rated MEDIUM with a CVSS base score of 5.5/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2025-21820?
Check the references section above for vendor advisories and patch information. Affected products include: Linux Linux Kernel.