cbcvebase.
CVE-2025-68757
published 2026-01-05

CVE-2025-68757: In the Linux kernel, the following vulnerability has been resolved: drm/vgem-fence: Fix potential deadlock on release A timer that expires a vgem fence…

PriorityP421high7.8
EPSS
0.17%
6.8th percentile
In the Linux kernel, the following vulnerability has been resolved: drm/vgem-fence: Fix potential deadlock on release A timer that expires a vgem fence automatically in 10 seconds is now released with timer_delete_sync() from fence->ops.release() called on last dma_fence_put(). In some scenarios, it can run in IRQ context, which is not safe unless TIMER_IRQSAFE is used. One potentially risky scenario was demonstrated in Intel DRM CI trybot, BAT run on machine bat-adlp-6, while working on new IGT subtests syncobj_timeline@stress-* as user space replacements of some problematic test cases of a dma-fence-chain selftest [1]. [117.004338] ================================ [117.004340] WARNING: inconsistent lock state [117.004342] 6.17.0-rc7-CI_DRM_17270-g7644974e648c+ #1 Tainted: G S U [117.004346] -------------------------------- [117.004347] inconsistent {HARDIRQ-ON-W} -> {IN-HARDIRQ-W} usage. [117.004349] swapper/0/0 [HC1[1]:SC1[1]:HE0:SE0] takes: [117.004352] ffff888138f86aa8 ((&fence->timer)){?.-.}-{0:0}, at: __timer_delete_sync+0x4b/0x190 [117.004361] {HARDIRQ-ON-W} state was registered at: [117.004363] lock_acquire+0xc4/0x2e0 [117.004366] call_timer_fn+0x80/0x2a0 [117.004368] __run_timers+0x231/0x310 [117.004370] run_timer_softirq+0x76/0xe0 [117.004372] handle_softirqs+0xd4/0x4d0 [117.004375] __irq_exit_rcu+0x13f/0x160 [117.004377] irq_exit_rcu+0xe/0x20 [117.004379] sysvec_apic_timer_interrupt+0xa0/0xc0 [117.004382] asm_sysvec_apic_timer_interrupt+0x1b/0x20 [117.004385] cpuidle_enter_state+0x12b/0x8a0 [117.004388] cpuidle_enter+0x2e/0x50 [117.004393] call_cpuidle+0x22/0x60 [117.004395] do_idle+0x1fd/0x260 [117.004398] cpu_startup_entry+0x29/0x30 [117.004401] start_secondary+0x12d/0x160 [117.004404] common_startup_64+0x13e/0x141 [117.004407] irq event stamp: 2282669 [117.004409] hardirqs last enabled at (2282668): [] _raw_spin_unlock_irqrestore+0x51/0x80 [117.004414] hardirqs last disabled at (2282669): [] sysvec_irq_work+0x11/0xc0 [117.004419] softirqs last enab

Affected

45 ranges· showing 25
VendorProductVersion rangeFixed in
debianlinux< linux 6.1.162-1 (bookworm)linux 6.1.162-1 (bookworm)
debianlinux-6.1< linux 6.1.162-1 (bookworm)linux 6.1.162-1 (bookworm)
linuxlinux
linuxlinux>= 4077798484459a2eced2050045099a466ecb618a < 37289a18099fc7ce916933bd542926a7334791a337289a18099fc7ce916933bd542926a7334791a3
linuxlinux>= 4077798484459a2eced2050045099a466ecb618a < 489b2158aec92a3fc256d70992416869f86e16e0489b2158aec92a3fc256d70992416869f86e16e0
linuxlinux>= 4077798484459a2eced2050045099a466ecb618a < 1026d1b0bd55e1be7ba0f9e9b1c9f6e02448f25a1026d1b0bd55e1be7ba0f9e9b1c9f6e02448f25a
linuxlinux>= 4077798484459a2eced2050045099a466ecb618a < 9dc3c78d21e16f5af1a9c3d11b4bd5276f891fe09dc3c78d21e16f5af1a9c3d11b4bd5276f891fe0
linuxlinux>= 4077798484459a2eced2050045099a466ecb618a < 338e388c0d80ffc04963b6b0ec702ffdfd2c4eba338e388c0d80ffc04963b6b0ec702ffdfd2c4eba
linuxlinux>= 4077798484459a2eced2050045099a466ecb618a < 4f335cb8fad69b2be5accf0ebac3a8b345915f4e4f335cb8fad69b2be5accf0ebac3a8b345915f4e
linuxlinux>= 4077798484459a2eced2050045099a466ecb618a < 1f0ca9d3e7c38a39f1f12377c24decf0bba46e541f0ca9d3e7c38a39f1f12377c24decf0bba46e54
linuxlinux>= 4077798484459a2eced2050045099a466ecb618a < 78b4d6463e9e69e5103f98b367f8984ad12cdc6f78b4d6463e9e69e5103f98b367f8984ad12cdc6f
linuxlinux_kernel>= 0 < 5.10.249-15.10.249-1
linuxlinux_kernel>= 0 < 6.1.162-16.1.162-1
linuxlinux_kernel>= 0 < 6.12.63-16.12.63-1
linuxlinux_kernel>= 0 < 6.17.13-16.17.13-1
linuxlinux_kernel>= 0 < 5.15.0-173.1835.15.0-173.183
linuxlinux_kernel>= 0 < 6.17.0-19.196.17.0-19.19
linuxlinux_kernel>= 4.8.0 < 5.10.2485.10.248
linuxlinux_kernel>= 5.11.0 < 5.15.1985.15.198
linuxlinux_kernel>= 5.16.0 < 6.1.1606.1.160
linuxlinux_kernel>= 6.13.0 < 6.17.136.17.13
linuxlinux_kernel>= 6.18.0 < 6.18.26.18.2
linuxlinux_kernel>= 6.2.0 < 6.6.1206.6.120
linuxlinux_kernel>= 6.7.0 < 6.12.636.12.63
ubuntulinux-aws-fips

CVSS provenance

osv7.8HIGH
vendor_ubuntu7.8HIGH
vendor_redhat6.2MEDIUM
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.