CVE-2025-38436
Severity CVSS v4.0:
Pending analysis
Type:
Unavailable / Other
Publication date:
25/07/2025
Last modified:
19/11/2025
Description
In the Linux kernel, the following vulnerability has been resolved:<br />
<br />
drm/scheduler: signal scheduled fence when kill job<br />
<br />
When an entity from application B is killed, drm_sched_entity_kill()<br />
removes all jobs belonging to that entity through<br />
drm_sched_entity_kill_jobs_work(). If application A&#39;s job depends on a<br />
scheduled fence from application B&#39;s job, and that fence is not properly<br />
signaled during the killing process, application A&#39;s dependency cannot be<br />
cleared.<br />
<br />
This leads to application A hanging indefinitely while waiting for a<br />
dependency that will never be resolved. Fix this issue by ensuring that<br />
scheduled fences are properly signaled when an entity is killed, allowing<br />
dependent applications to continue execution.
Impact
Base Score 3.x
5.50
Severity 3.x
MEDIUM
Vulnerable products and versions
| CPE | From | Up to |
|---|---|---|
| cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:* | 4.3 (including) | 6.6.96 (excluding) |
| cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:* | 6.7 (including) | 6.12.36 (excluding) |
| cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:* | 6.13 (including) | 6.15.5 (excluding) |
To consult the complete list of CPE names with products and versions, see this page



