PT-2025-22169 · Linux+4 · Linux Kernel+4

Published

2025-01-09

·

Updated

2026-05-26

·

CVE-2025-37907

CVSS v3.1

5.5

Medium

VectorAV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
Name of the Vulnerable Software and Affected Versions Linux kernel (affected versions not specified)
Description A deadlock issue in the Linux kernel has been identified, specifically in the ivpu job submit function. This occurs due to an incorrect locking order when a thread aborts currently executing jobs due to a fault. The thread first locks the global lock protecting submitted jobs, then releases the related context and locks file priv. However, in the job submission thread, the file priv lock is taken first, followed by the submitted jobs lock. This locking order causes a deadlock. The issue is resolved by changing the order of locking in ivpu job submit.
Recommendations To resolve this issue, change the order of locking in the ivpu job submit function to avoid the deadlock. As a temporary workaround, consider disabling the job submission functionality until a patch is available. Restrict access to the ivpu job submit function to minimize the risk of exploitation.

Exploit

Fix

Improper Locking

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

AZL-62821
BDU:2025-12337
CVE-2025-37907
ECHO-E9E7-8EC9-8C30
USN-7649-1
USN-7649-2
USN-7650-1
USN-7665-1
USN-7665-2
USN-7721-1

Affected Products

Astra Linux
Debian
Linuxmint
Linux Kernel
Ubuntu