CVE-2025-38436

Severity CVSS v4.0:
Pending analysis
Type:
Unavailable / Other
Publication date:
25/07/2025
Last modified:
19/11/2025

Description

In the Linux kernel, the following vulnerability has been resolved:<br /> <br /> drm/scheduler: signal scheduled fence when kill job<br /> <br /> When an entity from application B is killed, drm_sched_entity_kill()<br /> removes all jobs belonging to that entity through<br /> drm_sched_entity_kill_jobs_work(). If application A&amp;#39;s job depends on a<br /> scheduled fence from application B&amp;#39;s job, and that fence is not properly<br /> signaled during the killing process, application A&amp;#39;s dependency cannot be<br /> cleared.<br /> <br /> This leads to application A hanging indefinitely while waiting for a<br /> dependency that will never be resolved. Fix this issue by ensuring that<br /> scheduled fences are properly signaled when an entity is killed, allowing<br /> dependent applications to continue execution.

Vulnerable products and versions

CPE From Up to
cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:* 4.3 (including) 6.6.96 (excluding)
cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:* 6.7 (including) 6.12.36 (excluding)
cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:* 6.13 (including) 6.15.5 (excluding)