cbcvebase.
CVE-2025-68223
published 2025-12-16

CVE-2025-68223: In the Linux kernel, the following vulnerability has been resolved: drm/radeon: delete radeon_fence_process in is_signaled, no deadlock Delete the attempt to…

PriorityP419medium5.5CVSS 3.1
AVLACLPRLUINSUCNINAH
EPSS
0.10%
1.2th percentile
In the Linux kernel, the following vulnerability has been resolved: drm/radeon: delete radeon_fence_process in is_signaled, no deadlock Delete the attempt to progress the queue when checking if fence is signaled. This avoids deadlock. dma-fence_ops::signaled can be called with the fence lock in unknown state. For radeon, the fence lock is also the wait queue lock. This can cause a self deadlock when signaled() tries to make forward progress on the wait queue. But advancing the queue is unneeded because incorrectly returning false from signaled() is perfectly acceptable. (cherry picked from commit 527ba26e50ec2ca2be9c7c82f3ad42998a75d0db)

Affected

26 ranges· showing 25
VendorProductVersion rangeFixed in
debianlinux< linux 6.1.162-1 (bookworm)linux 6.1.162-1 (bookworm)
debianlinux-6.1< linux 6.1.162-1 (bookworm)linux 6.1.162-1 (bookworm)
linuxlinux
linuxlinux>= 954605ca3f897ad617123279eb3404a404cce5ab < d40a72d7e3bad4dfb311ef078f5a57362f088c7fd40a72d7e3bad4dfb311ef078f5a57362f088c7f
linuxlinux>= 954605ca3f897ad617123279eb3404a404cce5ab < 9d0ed508a9e2af82951ce7d834f58c139fc2bd9b9d0ed508a9e2af82951ce7d834f58c139fc2bd9b
linuxlinux>= 954605ca3f897ad617123279eb3404a404cce5ab < 73bc12d6a547f9571ce4393acfd73c004e2df9e573bc12d6a547f9571ce4393acfd73c004e2df9e5
linuxlinux>= 954605ca3f897ad617123279eb3404a404cce5ab < 7e3e9b3a44c23c8eac86a41308c05077d6d30f417e3e9b3a44c23c8eac86a41308c05077d6d30f41
linuxlinux>= 954605ca3f897ad617123279eb3404a404cce5ab < 9eb00b5f5697bd56baa3222c7a1426fa15bacfb59eb00b5f5697bd56baa3222c7a1426fa15bacfb5
linuxlinux_kernel
linuxlinux_kernel>= 0 < 6.1.162-16.1.162-1
linuxlinux_kernel>= 0 < 6.12.63-16.12.63-1
linuxlinux_kernel>= 0 < 6.17.10-16.17.10-1
linuxlinux_kernel>= 0 < 6.8.0-106.1066.8.0-106.106
linuxlinux_kernel>= 0 < 6.17.0-19.196.17.0-19.19
linuxlinux_kernel>= 3.18 < 6.1.1626.1.162
linuxlinux_kernel>= 6.13 < 6.17.106.17.10
linuxlinux_kernel>= 6.2 < 6.6.1236.6.123
linuxlinux_kernel>= 6.7 < 6.12.606.12.60
msrcazl3_kernel_6.6.117.1-1_on_azure_linux_3.0
msrcazl3_kernel_6.6.119.3-1_on_azure_linux_3.0
msrcazl3_kernel_6.6.119.3-3_on_azure_linux_3.0
msrcazl3_kernel_6.6.121.1-1_on_azure_linux_3.0
msrccbl2_kernel_5.15.186.1-1_on_cbl_mariner_2.0
msrccbl2_kernel_5.15.200.1-1_on_cbl_mariner_2.0
msrccbl2_kernel_5.15.202.1-1_on_cbl_mariner_2.0

CVSS provenance

nvdv3.15.5MEDIUMCVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
osv7.2HIGH
vendor_ubuntu7.8HIGH
vendor_msrc6.2MEDIUM
vendor_debian5.5MEDIUM
vendor_redhat5.5MEDIUM
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.