Database/Kernel, userspace & hypervisor
Linux kernel (drivers/gpu/drm/scheduler): Tearing down a GPU scheduler entity takes locks from a fence-signalling
Impact
Tearing down a GPU scheduler entity takes locks from a fence-signalling callback that runs in interrupt context, so a tenant whose jobs carry cross-fence dependencies can wedge the CPU that is signalling and the shared GPU scheduler behind it. This is a whole-node outage vector: the scheduler is shared by every tenant on the device, and a deadlock there stalls all of their queues, not just the attacker's.
Who can reach it
An unprivileged process in a container holding /dev/dri/renderD* reaches this by submitting jobs with dependencies on other fences and then dying or being killed, which is exactly what a crashing or OOM-killed workload does. The code is in the shared drm/scheduler layer, so amdgpu, xe, nouveau, panfrost and every other scheduler user is affected, not one vendor.
What to do
Update to a kernel with the fix commits below, which moves the dependency re-arming out of the fence callback into a work item. No interim control short of removing GPU access; the trigger is normal process teardown.
References
Related entries
- Linux kernel (drivers/gpu/drm/scheduler): When a process is killed with GPU work still queued, the scheduler entityCVE-2022-49829 · Linux kernel (drivers/gpu/drm/scheduler)Medium
- Linux kernel (drivers/gpu/drm/scheduler): When adding reservation-object dependencies to a job, the helper alreadyCVE-2025-40096 · Linux kernel (drivers/gpu/drm/scheduler)High
- Linux kernel (drivers/gpu/drm/scheduler): When one tenant's scheduler entity is killed, its scheduled fences are notCVE-2025-38436 · Linux kernel (drivers/gpu/drm/scheduler)Medium
- Intel CPU (MDS / ZombieLoad): Microarchitectural Fill Buffer Data SamplingCVE-2018-12130 · Intel CPU (MDS / ZombieLoad)Medium
- Linux kernel (drivers/pci): Pci_dev_lock() and the sysfs SR-IOV path took the device lock and the config-space accessCVE-2022-49434 · Linux kernel (drivers/pci)Medium
- OpenSSH (transport): Terrapin: prefix-truncation attack on the SSH Binary Packet ProtocolCVE-2023-48795 · OpenSSH (transport)Medium
This entry is curated: imported from vendor advisories with machine assistance, not yet individually verified. Confirm against your vendor's advisory before acting, and report anything wrong.