CVE-2025-38436
In the Linux kernel, the following vulnerability has been resolved: drm/scheduler: signal scheduled fence when kill job When an entity from application B is killed, drm_sched_entity_kill() removes all jobs belonging to that entity through…
Does this matter?
Lower severity and a low EPSS score (0.13%). Track it; it rarely justifies an emergency change on its own.
Description
In the Linux kernel, the following vulnerability has been resolved: drm/scheduler: signal scheduled fence when kill job When an entity from application B is killed, drm_sched_entity_kill() removes all jobs belonging to that entity through drm_sched_entity_kill_jobs_work(). If application A's job depends on a scheduled fence from application B's job, and that fence is not properly signaled during the killing process, application A's dependency cannot be cleared. This leads to application A hanging indefinitely while waiting for a dependency that will never be resolved. Fix this issue by ensuring that scheduled fences are properly signaled when an entity is killed, allowing dependent applications to continue execution.
- CVSS 3.1
- 5.5 MEDIUMCVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
- EPSS
- 0.13% probability · 3th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-667
- Affected
- linux/linux kernel
- Source
- 416baaa9-dc9f-4396-8d5f-8c081fb06d67
References
- https://git.kernel.org/stable/c/471db2c2d4f80ee94225a1ef246e4f5011733e50Patch
- https://git.kernel.org/stable/c/8342127a8a65b0673863b106ce32b79c91ae3270
- https://git.kernel.org/stable/c/aa382a8b6ed483e9812d0e63b6d1bdcba0186f29Patch
- https://git.kernel.org/stable/c/aefd0a935625165a6ca36d0258d2d053901555dfPatch
- https://git.kernel.org/stable/c/c5734f9bab6f0d40577ad0633af4090a5fda2407Patch
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.