Junglewise Threat Intelligence

CVE-2025-40096: Linux Kernel DRM scheduler double free in job dependency handling

CVE-2025-40096 · Severity: high · CVSS 7.8 · Published 2025-10-30

Technologies: Linux Kernel. Vendors: Linux.

Executive brief

A vulnerability was identified in the Linux kernel's Direct Rendering Manager (DRM) scheduler, which manages how graphics tasks are sent to hardware. A flaw in how the system tracks task dependencies could lead to a system crash or memory corruption. This issue primarily affects local users on systems running affected versions of the Linux kernel.

Technical details

A double-free vulnerability exists in the drm_sched_job_add_resv_dependencies function within the Linux kernel's DRM scheduler (drivers/gpu/drm/scheduler/sched_main.c). The root cause is that drm_sched_job_add_dependency() consumes a fence reference on both success and failure; however, the error path in the caller also attempted to release the same reference using dma_fence_put() when an xarray expansion failed. This flaw has persisted through several previous fix attempts. The vulnerability is reachable by local users and can lead to memory corruption or a kernel panic. Patches have been released for various stable kernel branches including 6.1.158, 6.6.114, and 6.12.55.

Affected products

  • Linux Linux Kernel v5.16 to v6.17.5

Timeline

  • 2025-10-15: disclosed: Initial patch submission by Tvrtko Ursulin
  • 2025-10-30: advisory: CVE-2025-40096 published

References

Related threats