cbcvebase.
CVE-2025-40329
published 2025-12-09

CVE-2025-40329: In the Linux kernel, the following vulnerability has been resolved: drm/sched: Fix deadlock in drm_sched_entity_kill_jobs_cb The Mesa issue referenced below…

PriorityP422high7.8
EPSS
0.20%
9.8th percentile
In the Linux kernel, the following vulnerability has been resolved: drm/sched: Fix deadlock in drm_sched_entity_kill_jobs_cb The Mesa issue referenced below pointed out a possible deadlock: [ 1231.611031] Possible interrupt unsafe locking scenario: [ 1231.611033] CPU0 CPU1 [ 1231.611034] ---- ---- [ 1231.611035] lock(&xa->xa_lock#17); [ 1231.611038] local_irq_disable(); [ 1231.611039] lock(&fence->lock); [ 1231.611041] lock(&xa->xa_lock#17); [ 1231.611044] [ 1231.611045] lock(&fence->lock); [ 1231.611047] *** DEADLOCK *** In this example, CPU0 would be any function accessing job->dependencies through the xa_* functions that don't disable interrupts (eg: drm_sched_job_add_dependency(), drm_sched_entity_kill_jobs_cb()). CPU1 is executing drm_sched_entity_kill_jobs_cb() as a fence signalling callback so in an interrupt context. It will deadlock when trying to grab the xa_lock which is already held by CPU0. Replacing all xa_* usage by their xa_*_irq counterparts would fix this issue, but Christian pointed out another issue: dma_fence_signal takes fence.lock and so does dma_fence_add_callback. dma_fence_signal() // locks f1.lock -> drm_sched_entity_kill_jobs_cb() -> foreach dependencies -> dma_fence_add_callback() // locks f2.lock This will deadlock if f1 and f2 share the same spinlock. To fix both issues, the code iterating on dependencies and re-arming them is moved out to drm_sched_entity_kill_jobs_work(). [phasta: commit message nits]

Affected

17 ranges
VendorProductVersion rangeFixed in
debianlinux< linux 6.17.8-1 (forky)linux 6.17.8-1 (forky)
linuxlinux
linuxlinux>= 2fdb8a8f07c2f1353770a324fd19b8114e4329ac < 70150b9443dddf02157d821c68abf438f55a2e8e70150b9443dddf02157d821c68abf438f55a2e8e
linuxlinux>= 2fdb8a8f07c2f1353770a324fd19b8114e4329ac < 0d63031ee4a57be0252cb9a4e09ae921c75cece90d63031ee4a57be0252cb9a4e09ae921c75cece9
linuxlinux>= 2fdb8a8f07c2f1353770a324fd19b8114e4329ac < 3e8ada4fd838e3fd2cca94000dac054f3a347c013e8ada4fd838e3fd2cca94000dac054f3a347c01
linuxlinux>= 2fdb8a8f07c2f1353770a324fd19b8114e4329ac < 487df8b698345dd5a91346335f05170ed5f29d4e487df8b698345dd5a91346335f05170ed5f29d4e
linuxlinux_kernel>= 0 < 6.12.63-16.12.63-1
linuxlinux_kernel>= 0 < 6.17.8-16.17.8-1
linuxlinux_kernel>= 0 < 6.8.0-106.1066.8.0-106.106
linuxlinux_kernel>= 0 < 6.17.0-14.146.17.0-14.14
linuxlinux_kernel>= 6.13.0 < 6.17.86.17.8
linuxlinux_kernel>= 6.2.0 < 6.6.1176.6.117
linuxlinux_kernel>= 6.7.0 < 6.12.586.12.58
msrcazl3_kernel_6.6.112.1-2_on_azure_linux_3.0
ubuntulinux-aws
ubuntulinux-oracle
ubuntulinux-xilinx

CVSS provenance

vendor_ubuntu7.8HIGH
osv3.2LOW
vendor_msrc7.0HIGH
vendor_redhat5.8MEDIUM
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.