CVE-2025-68223
In the Linux kernel, the following vulnerability has been resolved:
drm/radeon: delete radeon_fence_process in is_signaled, no deadlock
Delete the attempt to progress the queue when checking if fence is signaled. This avoids deadlock.
dma-fence_ops::signaled can be called with the fence lock in unknown state. For radeon, the fence lock is also the wait queue lock. This can cause a self deadlock when signaled() tries to make forward progress on the wait queue. But advancing the queue is unneeded because incorrectly returning false from signaled() is perfectly acceptable.
(cherry picked from commit 527ba26e50ec2ca2be9c7c82f3ad42998a75d0db)
CVSS
- Versión: 3.1
- Vector: CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
- Puntuación base: 5.5
Probabilidad de explotación (EPSS)
- Probabilidad de explotación en los próximos 30 días: 0.12%
- Percentil entre todas las CVEs puntuadas: 1
- Fecha de la puntuación: 6/10/2026
EPSS (Exploit Prediction Scoring System, de FIRST) estima la probabilidad de que una vulnerabilidad sea explotada en 30 días. Complementa a CVSS (impacto) y a CISA KEV (explotación confirmada).
Tecnologías afectadas (1)
CWE
- CWE-667
Referencias
- https://git.kernel.org/stable/c/73bc12d6a547f9571ce4393acfd73c004e2df9e5
- https://git.kernel.org/stable/c/7e3e9b3a44c23c8eac86a41308c05077d6d30f41
- https://git.kernel.org/stable/c/9d0ed508a9e2af82951ce7d834f58c139fc2bd9b
- https://git.kernel.org/stable/c/9eb00b5f5697bd56baa3222c7a1426fa15bacfb5
- https://git.kernel.org/stable/c/d40a72d7e3bad4dfb311ef078f5a57362f088c7f
JSON original (NVD)
Mostrar
{
"id": "CVE-2025-68223",
"cveTags": [],
"metrics": {
"cvssMetricV31": [
{
"type": "Primary",
"source": "nvd@nist.gov",
"cvssData": {
"scope": "UNCHANGED",
"version": "3.1",
"baseScore": 5.5,
"attackVector": "LOCAL",
"baseSeverity": "MEDIUM",
"vectorString": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H",
"integrityImpact": "NONE",
"userInteraction": "NONE",
"attackComplexity": "LOW",
"availabilityImpact": "HIGH",
"privilegesRequired": "LOW",
"confidentialityImpact": "NONE"
},
"impactScore": 3.6,
"exploitabilityScore": 1.8
}
]
},
"affected": [
{
"source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"affectedData": [
{
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"product": "Linux",
"versions": [
{
"status": "affected",
"version": "954605ca3f897ad617123279eb3404a404cce5ab",
"lessThan": "d40a72d7e3bad4dfb311ef078f5a57362f088c7f",
"versionType": "git"
},
{
"status": "affected",
"version": "954605ca3f897ad617123279eb3404a404cce5ab",
"lessThan": "9d0ed508a9e2af82951ce7d834f58c139fc2bd9b",
"versionType": "git"
},
{
"status": "affected",
"version": "954605ca3f897ad617123279eb3404a404cce5ab",
"lessThan": "73bc12d6a547f9571ce4393acfd73c004e2df9e5",
"versionType": "git"
},
{
"status": "affected",
"version": "954605ca3f897ad617123279eb3404a404cce5ab",
"lessThan": "7e3e9b3a44c23c8eac86a41308c05077d6d30f41",
"versionType": "git"
},
{
"status": "affected",
"version": "954605ca3f897ad617123279eb3404a404cce5ab",
"lessThan": "9eb00b5f5697bd56baa3222c7a1426fa15bacfb5",
"versionType": "git"
}
],
"programFiles": [
"drivers/gpu/drm/radeon/radeon_fence.c"
],
"defaultStatus": "unaffected"
},
{
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"product": "Linux",
"versions": [
{
"status": "affected",
"version": "3.18"
},
{
"status": "unaffected",
"version": "0",
"lessThan": "3.18",
"versionType": "semver"
},
{
"status": "unaffected",
"version": "6.1.162",
"versionType": "semver",
"lessThanOrEqual": "6.1.*"
},
{
"status": "unaffected",
"version": "6.6.123",
"versionType": "semver",
"lessThanOrEqual": "6.6.*"
},
{
"status": "unaffected",
"version": "6.12.60",
"versionType": "semver",
"lessThanOrEqual": "6.12.*"
},
{
"status": "unaffected",
"version": "6.17.10",
"versionType": "semver",
"lessThanOrEqual": "6.17.*"
},
{
"status": "unaffected",
"version": "6.18",
"versionType": "original_commit_for_fix",
"lessThanOrEqual": "*"
}
],
"programFiles": [
"drivers/gpu/drm/radeon/radeon_fence.c"
],
"defaultStatus": "affected"
}
]
}
],
"published": "2025-12-16T14:15:55.630",
"references": [
{
"url": "https://git.kernel.org/stable/c/73bc12d6a547f9571ce4393acfd73c004e2df9e5",
"tags": [
"Patch"
],
"source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
},
{
"url": "https://git.kernel.org/stable/c/7e3e9b3a44c23c8eac86a41308c05077d6d30f41",
"tags": [
"Patch"
],
"source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
},
{
"url": "https://git.kernel.org/stable/c/9d0ed508a9e2af82951ce7d834f58c139fc2bd9b",
"tags": [
"Patch"
],
"source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
},
{
"url": "https://git.kernel.org/stable/c/9eb00b5f5697bd56baa3222c7a1426fa15bacfb5",
"tags": [
"Patch"
],
"source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
},
{
"url": "https://git.kernel.org/stable/c/d40a72d7e3bad4dfb311ef078f5a57362f088c7f",
"tags": [
"Patch"
],
"source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
}
],
"vulnStatus": "Analyzed",
"weaknesses": [
{
"type": "Primary",
"source": "nvd@nist.gov",
"description": [
{
"lang": "en",
"value": "CWE-667"
}
]
}
],
"descriptions": [
{
"lang": "en",
"value": "In the Linux kernel, the following vulnerability has been resolved:\n\ndrm/radeon: delete radeon_fence_process in is_signaled, no deadlock\n\nDelete the attempt to progress the queue when checking if fence is\nsignaled. This avoids deadlock.\n\ndma-fence_ops::signaled can be called with the fence lock in unknown\nstate. For radeon, the fence lock is also the wait queue lock. This can\ncause a self deadlock when signaled() tries to make forward progress on\nthe wait queue. But advancing the queue is unneeded because incorrectly\nreturning false from signaled() is perfectly acceptable.\n\n(cherry picked from commit 527ba26e50ec2ca2be9c7c82f3ad42998a75d0db)"
}
],
"lastModified": "2026-06-17T09:58:45.773",
"configurations": [
{
"nodes": [
{
"negate": false,
"cpeMatch": [
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "F0B0769E-C2FC-48CD-A03A-CBBDA8416EFF",
"versionEndExcluding": "6.1.162",
"versionStartIncluding": "3.18"
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "316D8D4E-FE44-4C76-8403-63CAF51EEFC2",
"versionEndExcluding": "6.6.123",
"versionStartIncluding": "6.2"
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "959A7F68-3804-4797-BE3E-A69E525AD284",
"versionEndExcluding": "6.12.60",
"versionStartIncluding": "6.7"
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "51C8475C-4E3F-464D-AE0C-4D52A8C3240E",
"versionEndExcluding": "6.17.10",
"versionStartIncluding": "6.13"
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:6.18:rc1:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "DD01661D-DFC8-4B6D-80E7-46D203CC4565"
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:6.18:rc2:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "A8A65C5A-918F-4E0B-8E98-08A29FFBA58A"
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:6.18:rc3:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "26CA425A-E44F-49D2-92D9-1DDD56398440"
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:6.18:rc4:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "BEEBB43A-4C9F-46BE-AA6D-9DBFD2244E55"
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:6.18:rc5:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "2545FB83-C4A6-4F62-9ED1-09F75D2E3C78"
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:6.18:rc6:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "E955EC5D-4684-4B5D-AE4D-F2BF9ADDBA1D"
}
],
"operator": "OR"
}
]
}
],
"sourceIdentifier": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
}