CVE-2025-38436: Linux Kernel

Medium severity, CVSS 5.5. EPSS: 0.1% chance of exploitation in the next 30 days.

In the Linux kernel, the following vulnerability has been resolved: drm/scheduler: signal scheduled fence when kill job When an entity from application B is killed, drm_sched_entity_kill() removes all jobs belonging to that entity through drm_sched_entity_kill_jobs_work(). If application A's job depends on a scheduled fence from application B's job, and that fence is not properly signaled during the killing process, application A's dependency cannot be cleared. This leads to application A hanging indefinitely while waiting for a dependency that will never be resolved. Fix this issue by ensuring that scheduled fences are properly signaled when an entity is killed, allowing dependent applications to continue execution.

Affected products

  • Linux Linux Kernel: from 4.3, before 6.6.96 (fixed in 6.6.96); from 6.7, before 6.12.36 (fixed in 6.12.36); from 6.13, before 6.15.5 (fixed in 6.15.5)

Published 2025-07-25. Last modified 2026-06-17.