CVE-2025-38521

HIGH

Linux Kernel - Denial of Service via GPU Hard Reset Sequence

Title source: llm
STIX 2.1

Description

In the Linux kernel, the following vulnerability has been resolved: drm/imagination: Fix kernel crash when hard resetting the GPU The GPU hard reset sequence calls pm_runtime_force_suspend() and pm_runtime_force_resume(), which according to their documentation should only be used during system-wide PM transitions to sleep states. The main issue though is that depending on some internal runtime PM state as seen by pm_runtime_force_suspend() (whether the usage count is <= 1), pm_runtime_force_resume() might not resume the device unless needed. If that happens, the runtime PM resume callback pvr_power_device_resume() is not called, the GPU clocks are not re-enabled, and the kernel crashes on the next attempt to access GPU registers as part of the power-on sequence. Replace calls to pm_runtime_force_suspend() and pm_runtime_force_resume() with direct calls to the driver's runtime PM callbacks, pvr_power_device_suspend() and pvr_power_device_resume(), to ensure clocks are re-enabled and avoid the kernel crash.

Scores

CVSS v3 7.1
EPSS 0.0014
EPSS Percentile 3.5%
Attack Vector LOCAL
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:H

Details

CWE
CWE-668
Status published
Products (12)
linux/Kernel 6.13.0 - 6.15.7linux
linux/Kernel 6.8.0 - 6.12.39linux
Linux/Linux < 6.8
Linux/Linux 6.12.39 - 6.12.*
Linux/Linux 6.15.7 - 6.15.*
Linux/Linux 6.16
Linux/Linux 6.8
Linux/Linux cc1aeedb98ad347c06ff59e991b2f94dfb4c565d - 9f852d301f642223c4798f3c13ba15e91165d078
Linux/Linux cc1aeedb98ad347c06ff59e991b2f94dfb4c565d - d38376b3ee48d073c64e75e150510d7e6b4b04f7
Linux/Linux cc1aeedb98ad347c06ff59e991b2f94dfb4c565d - e066cc6e0f094ca2120f1928d126d56f686cd73e
... and 2 more
Published Aug 16, 2025
Tracked Since Feb 18, 2026