cbcvebase.
CVE-2025-37965
published 2025-05-20

CVE-2025-37965: In the Linux kernel, the following vulnerability has been resolved: drm/amd/display: Fix invalid context error in dml helper [Why] "BUG: sleeping function…

PriorityP418medium5.5CVSS 3.1
AVLACLPRLUINSUCNINAH
EPSS
0.16%
5.8th percentile
In the Linux kernel, the following vulnerability has been resolved: drm/amd/display: Fix invalid context error in dml helper [Why] "BUG: sleeping function called from invalid context" error. after: "drm/amd/display: Protect FPU in dml2_validate()/dml21_validate()" The populate_dml_plane_cfg_from_plane_state() uses the GFP_KERNEL flag for memory allocation, which shouldn't be used in atomic contexts. The allocation is needed only for using another helper function get_scaler_data_for_plane(). [How] Modify helpers to pass a pointer to scaler_data within existing context, eliminating the need for dynamic memory allocation/deallocation and copying. (cherry picked from commit bd3e84bc98f81b44f2c43936bdadc3241d654259)

Affected

11 ranges
VendorProductVersion rangeFixed in
debianlinux< linux 6.12.29-1 (forky)linux 6.12.29-1 (forky)
linuxlinux>= 366e77cd4923c3aa45341e15dcaf3377af9b042f < 9984db63742099ee3f3cff35cf71306d10e643569984db63742099ee3f3cff35cf71306d10e64356
linuxlinux>= 6.12.25 < 6.12.296.12.29
linuxlinux>= 6.14.4 < 6.14.76.14.7
linuxlinux>= 74d6fba60f05ca6b298702233b6e6cc7629eeb5a < d8c4afe78385cd355e4d80299d785379d6e874dfd8c4afe78385cd355e4d80299d785379d6e874df
linuxlinux>= 7b80dcf343d45088931d16a6c9ba2fd975138a0b < b371f8f6d89ec8dfea796e00a44a57c44fc8fcc0b371f8f6d89ec8dfea796e00a44a57c44fc8fcc0
linuxlinux_kernel
linuxlinux_kernel>= 0 < 6.12.29-16.12.29-1
linuxlinux_kernel>= 0 < 6.12.29-16.12.29-1
linuxlinux_kernel>= 6.12.25 < 6.12.296.12.29
linuxlinux_kernel>= 6.14.4 < 6.14.76.14.7

CVSS provenance

nvdv3.15.5MEDIUMCVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
osv7.8HIGH
vendor_ubuntu7.8HIGH
vendor_debian5.5LOW
vendor_redhat5.5MEDIUM
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.