CVE-2025-37951 Details
Description
In the Linux kernel, the following vulnerability has been resolved: drm/v3d: Add job to pending list if the reset was skipped When a CL/CSD job times out, we check if the GPU has made any progress since the last timeout. If so, instead of resetting the hardware, we skip the reset and let the timer get rearmed. This gives long-running jobs a chance to complete. However, when `timedout_job()` is called, the job in question is removed from the pending list, which means it won't be automatically freed through `free_job()`. Consequently, when we skip the reset and keep the job running, the job won't be freed when it finally completes. This situation leads to a memory leak, as exposed in [1] and [2]. Similarly to commit 704d3d60fec4 ("drm/etnaviv: don't block scheduler when GPU is still active"), this patch ensures the job is put back on the pending list when extending the timeout.
A memory leak vulnerability has been identified in the Linux kernel's Direct Rendering Manager (DRM) V3D component. This issue arises when a job in the Command List/Compute Shader (CL/CSD) stage times out. Instead of resetting the hardware, the timeout is skipped to allow long-running jobs a chance to complete. However, this process removes the job from the pending list, preventing it from being properly freed once it finishes. As a result, the skipped reset leads to a memory leak, as the job remains active without being released. This vulnerability has been addressed by ensuring that jobs are reinstated on the pending list when their timeout is extended, similar to a previous fix in the DRM Etnaviv component.
Metrics
CVSS 4.0 Severity and Vector Strings:
No CVSS 4.0 data is available for this CVE.
CVSS 3.x Severity and Vector Strings:
No data available for CVSS Version 2.0 on this CVE.
No SSVC data is available for this CVE.
References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.
| URL | Source(s) | Tag(s) |
|---|---|---|
| https://git.kernel.org/stable/c/12125f7d9c15e6d8ac91d10373b2db2f17dcf767 | kernel.org | Patch |
| https://git.kernel.org/stable/c/35e4079bf1a2570abffce6ababa631afcf8ea0e5 | kernel.org | Patch |
| https://git.kernel.org/stable/c/422a8b10ba42097a704d6909ada2956f880246f2 | kernel.org | Patch |
| https://git.kernel.org/stable/c/5235b56b7e5449d990d21d78723b1a5e7bb5738e | kernel.org | Patch |
| https://git.kernel.org/stable/c/a5f162727b91e480656da1876247a91f651f76de | kernel.org | Patch |
| https://lists.debian.org/debian-lts-announce/2025/08/msg00010.html | CVE | Third Party Advisory |
Weakness Enumeration
| CWE-ID | CWE Name | Source |
|---|---|---|
| CWE-401 | Missing Release of Memory after Effective Lifetime | [email protected] |
Affected Products
| Product | Versions |
|---|---|
| linux linux kernel | >= 4.18, < 6.1.139 >= 6.2, < 6.6.91 >= 6.7, < 6.12.29 >= 6.13, < 6.14.7 6.15 rc1 6.15 rc2 6.15 rc3 6.15 rc4 6.15 rc5 |
CPE
Remediation
| |
| debian debian linux | 11.0 |
CPE
Remediation
| |
Change History
4 change records found show changes
| Date | Action | Recorded By |
|---|---|---|
| Jun 17, 2026 | CVE Modified | kernel.org |
| Dec 17, 2025 | Initial Analysis | [email protected] |
| Nov 3, 2025 | CVE Modified | CVE |
| May 20, 2025 | New CVE Received | kernel.org |