cbcvebase.
CVE-2025-38436
published 2025-07-25

CVE-2025-38436: In the Linux kernel, the following vulnerability has been resolved: drm/scheduler: signal scheduled fence when kill job When an entity from application B is…

PriorityP419medium5.5CVSS 3.1
AVLACLPRLUINSUCNINAH
EPSS
0.13%
2.7th percentile
In the Linux kernel, the following vulnerability has been resolved: drm/scheduler: signal scheduled fence when kill job When an entity from application B is killed, drm_sched_entity_kill() removes all jobs belonging to that entity through drm_sched_entity_kill_jobs_work(). If application A's job depends on a scheduled fence from application B's job, and that fence is not properly signaled during the killing process, application A's dependency cannot be cleared. This leads to application A hanging indefinitely while waiting for a dependency that will never be resolved. Fix this issue by ensuring that scheduled fences are properly signaled when an entity is killed, allowing dependent applications to continue execution.

Affected

27 ranges· showing 25
VendorProductVersion rangeFixed in
debianlinux< linux 6.12.37-1 (forky)linux 6.12.37-1 (forky)
linuxlinux
linuxlinux>= a72ce6f84109c1dec1ab236d65979d3250668af3 < 8342127a8a65b0673863b106ce32b79c91ae32708342127a8a65b0673863b106ce32b79c91ae3270
linuxlinux>= a72ce6f84109c1dec1ab236d65979d3250668af3 < c5734f9bab6f0d40577ad0633af4090a5fda2407c5734f9bab6f0d40577ad0633af4090a5fda2407
linuxlinux>= a72ce6f84109c1dec1ab236d65979d3250668af3 < aefd0a935625165a6ca36d0258d2d053901555dfaefd0a935625165a6ca36d0258d2d053901555df
linuxlinux>= a72ce6f84109c1dec1ab236d65979d3250668af3 < aa382a8b6ed483e9812d0e63b6d1bdcba0186f29aa382a8b6ed483e9812d0e63b6d1bdcba0186f29
linuxlinux>= a72ce6f84109c1dec1ab236d65979d3250668af3 < 471db2c2d4f80ee94225a1ef246e4f5011733e50471db2c2d4f80ee94225a1ef246e4f5011733e50
linuxlinux_kernel>= 0 < 6.12.37-16.12.37-1
linuxlinux_kernel>= 0 < 6.12.37-16.12.37-1
linuxlinux_kernel>= 0 < 6.8.0-100.1006.8.0-100.100
linuxlinux_kernel>= 4.3 < 6.6.966.6.96
linuxlinux_kernel>= 6.13 < 6.15.56.15.5
linuxlinux_kernel>= 6.7 < 6.12.366.12.36
msrcazl3_kernel_6.6.92.2-2_on_azure_linux_3.0
msrcazl3_kernel_6.6.96.1-1_on_azure_linux_3.0
msrccbl2_kernel_5.15.186.1-1_on_cbl_mariner_2.0
msrccbl2_kernel_5.15.200.1-1_on_cbl_mariner_2.0
msrccbl2_kernel_5.15.202.1-1_on_cbl_mariner_2.0
ubuntulinux-aws
ubuntulinux-aws-6.8
ubuntulinux-gkeop
ubuntulinux-nvidia
ubuntulinux-nvidia-6.8
ubuntulinux-oracle
ubuntulinux-oracle-6.8

CVSS provenance

nvdv3.15.5MEDIUMCVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
osv5.6MEDIUM
vendor_ubuntu5.6MEDIUM
vendor_debian5.5MEDIUM
vendor_msrc5.5MEDIUM
vendor_redhat5.5MEDIUM
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.