Executive brief
A vulnerability was identified in the Linux kernel's Direct Rendering Manager (DRM) scheduler, which manages how graphics tasks are sent to hardware. A flaw in how the system tracks task dependencies could lead to a system crash or memory corruption. This issue primarily affects local users on systems running affected versions of the Linux kernel.
Technical details
A double-free vulnerability exists in the drm_sched_job_add_resv_dependencies function within the Linux kernel's DRM scheduler (drivers/gpu/drm/scheduler/sched_main.c). The root cause is that drm_sched_job_add_dependency() consumes a fence reference on both success and failure; however, the error path in the caller also attempted to release the same reference using dma_fence_put() when an xarray expansion failed. This flaw has persisted through several previous fix attempts. The vulnerability is reachable by local users and can lead to memory corruption or a kernel panic. Patches have been released for various stable kernel branches including 6.1.158, 6.6.114, and 6.12.55.
Affected products
- Linux Linux Kernel v5.16 to v6.17.5
Timeline
- 2025-10-15: disclosed: Initial patch submission by Tvrtko Ursulin
- 2025-10-30: advisory: CVE-2025-40096 published
References
- https://git.kernel.org/stable/c/4c38a63ae12ecc9370a7678077bde2d61aa80e9c
- https://git.kernel.org/stable/c/57239762aa90ad768dac055021f27705dae73344
- https://git.kernel.org/stable/c/5801e65206b065b0b2af032f7f1eef222aa2fd83
- https://git.kernel.org/stable/c/e5e3eb2aff92994ee81ce633f1c4e73bd4b87e11
- https://git.kernel.org/stable/c/fdfb47e85af1e11ec822c82739dde2dd8dff5115