« Volver al listado

CVE-2025-71314

Estado: AnalizadaMedia (5.5)—

In the Linux kernel, the following vulnerability has been resolved:

drm/panthor: Recover from panthor_gpu_flush_caches() failures

We have seen a few cases where the whole memory subsystem is blocked and flush operations never complete. When that happens, we want to:

Note that we drop the WARN_ON()s because these hangs can be triggered with buggy GPU jobs created by the UMD, and there's no way we can prevent it. We do keep the error messages though.

v2: - New patch

v3: - Collect R-b - Explicitly mention the fact we dropped the WARN_ON()s in the commit message

v4: - No changes

Detalles técnicos trazas, registros y código del informe original
- schedule a reset, so we can recover from this situation
- in the reset path, we need to reset the pending_reqs so we can send
  new commands after the reset
- if more panthor_gpu_flush_caches() operations are queued after
  the timeout, we skip them and return -EIO directly to avoid needless
  waits (the memory block won't miraculously work again)

CVSS

Probabilidad de explotación (EPSS)

EPSS (Exploit Prediction Scoring System, de FIRST) estima la probabilidad de que una vulnerabilidad sea explotada en 30 días. Complementa a CVSS (impacto) y a CISA KEV (explotación confirmada).

Tecnologías afectadas (1)

CWE

Referencias

JSON original (NVD)

Mostrar
{
  "id": "CVE-2025-71314",
  "cveTags": [],
  "metrics": {
    "cvssMetricV31": [
      {
        "type": "Primary",
        "source": "nvd@nist.gov",
        "cvssData": {
          "scope": "UNCHANGED",
          "version": "3.1",
          "baseScore": 5.5,
          "attackVector": "LOCAL",
          "baseSeverity": "MEDIUM",
          "vectorString": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H",
          "integrityImpact": "NONE",
          "userInteraction": "NONE",
          "attackComplexity": "LOW",
          "availabilityImpact": "HIGH",
          "privilegesRequired": "LOW",
          "confidentialityImpact": "NONE"
        },
        "impactScore": 3.6,
        "exploitabilityScore": 1.8
      }
    ]
  },
  "affected": [
    {
      "source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
      "affectedData": [
        {
          "repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
          "vendor": "Linux",
          "product": "Linux",
          "versions": [
            {
              "status": "affected",
              "version": "5cd894e258c4b0b92b9b475309cea244e590d194",
              "lessThan": "8ec4f1b14a6147db07d6e51aa1d6bcc799649847",
              "versionType": "git"
            },
            {
              "status": "affected",
              "version": "5cd894e258c4b0b92b9b475309cea244e590d194",
              "lessThan": "57753f2c64c033a21a7400b3a2192db1cd6c890e",
              "versionType": "git"
            },
            {
              "status": "affected",
              "version": "5cd894e258c4b0b92b9b475309cea244e590d194",
              "lessThan": "2c899c6026fc9d39286735b30c4d8550d4ea075b",
              "versionType": "git"
            },
            {
              "status": "affected",
              "version": "5cd894e258c4b0b92b9b475309cea244e590d194",
              "lessThan": "3c0a60195b37af83bbbaf223cd3a78945bace49e",
              "versionType": "git"
            }
          ],
          "programFiles": [
            "drivers/gpu/drm/panthor/panthor_gpu.c"
          ],
          "defaultStatus": "unaffected"
        },
        {
          "repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
          "vendor": "Linux",
          "product": "Linux",
          "versions": [
            {
              "status": "affected",
              "version": "6.10"
            },
            {
              "status": "unaffected",
              "version": "0",
              "lessThan": "6.10",
              "versionType": "semver"
            },
            {
              "status": "unaffected",
              "version": "6.12.75",
              "versionType": "semver",
              "lessThanOrEqual": "6.12.*"
            },
            {
              "status": "unaffected",
              "version": "6.18.14",
              "versionType": "semver",
              "lessThanOrEqual": "6.18.*"
            },
            {
              "status": "unaffected",
              "version": "6.19.4",
              "versionType": "semver",
              "lessThanOrEqual": "6.19.*"
            },
            {
              "status": "unaffected",
              "version": "7.0",
              "versionType": "original_commit_for_fix",
              "lessThanOrEqual": "*"
            }
          ],
          "programFiles": [
            "drivers/gpu/drm/panthor/panthor_gpu.c"
          ],
          "defaultStatus": "affected"
        }
      ]
    }
  ],
  "published": "2026-06-03T18:16:19.270",
  "references": [
    {
      "url": "https://git.kernel.org/stable/c/2c899c6026fc9d39286735b30c4d8550d4ea075b",
      "tags": [
        "Patch"
      ],
      "source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
    },
    {
      "url": "https://git.kernel.org/stable/c/3c0a60195b37af83bbbaf223cd3a78945bace49e",
      "tags": [
        "Patch"
      ],
      "source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
    },
    {
      "url": "https://git.kernel.org/stable/c/57753f2c64c033a21a7400b3a2192db1cd6c890e",
      "tags": [
        "Patch"
      ],
      "source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
    },
    {
      "url": "https://git.kernel.org/stable/c/8ec4f1b14a6147db07d6e51aa1d6bcc799649847",
      "tags": [
        "Patch"
      ],
      "source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
    }
  ],
  "vulnStatus": "Analyzed",
  "weaknesses": [
    {
      "type": "Primary",
      "source": "nvd@nist.gov",
      "description": [
        {
          "lang": "en",
          "value": "NVD-CWE-noinfo"
        }
      ]
    }
  ],
  "descriptions": [
    {
      "lang": "en",
      "value": "In the Linux kernel, the following vulnerability has been resolved:\n\ndrm/panthor: Recover from panthor_gpu_flush_caches() failures\n\nWe have seen a few cases where the whole memory subsystem is blocked\nand flush operations never complete. When that happens, we want to:\n\n- schedule a reset, so we can recover from this situation\n- in the reset path, we need to reset the pending_reqs so we can send\n  new commands after the reset\n- if more panthor_gpu_flush_caches() operations are queued after\n  the timeout, we skip them and return -EIO directly to avoid needless\n  waits (the memory block won't miraculously work again)\n\nNote that we drop the WARN_ON()s because these hangs can be triggered\nwith buggy GPU jobs created by the UMD, and there's no way we can\nprevent it. We do keep the error messages though.\n\nv2:\n- New patch\n\nv3:\n- Collect R-b\n- Explicitly mention the fact we dropped the WARN_ON()s in the commit\n  message\n\nv4:\n- No changes"
    },
    {
      "lang": "es",
      "value": "En el kernel de Linux, la siguiente vulnerabilidad ha sido resuelta:\n\ndrm/panthor: Recuperarse de fallos de panthor_gpu_flush_caches()\n\nHemos visto algunos casos donde todo el subsistema de memoria está bloqueado y las operaciones de vaciado nunca se completan. Cuando eso sucede, queremos:\n\n- programar un reinicio, para que podamos recuperarnos de esta situación\n- en la ruta de reinicio, necesitamos reiniciar los pending_reqs para que podamos enviar nuevos comandos después del reinicio\n- si más operaciones de panthor_gpu_flush_caches() se ponen en cola después del tiempo de espera, las omitimos y devolvemos -EIO directamente para evitar esperas innecesarias (el bloque de memoria no volverá a funcionar milagrosamente)\n\nTenga en cuenta que eliminamos los WARN_ON() porque estos bloqueos pueden ser provocados con trabajos de GPU defectuosos creados por el UMD, y no hay forma de que podamos evitarlo. Sí mantenemos los mensajes de error, sin embargo.\n\nv2:\n- Nuevo parche\n\nv3:\n- Recopilar R-b\n- Mencionar explícitamente el hecho de que eliminamos los WARN_ON() en el mensaje de commit\n\nv4:\n- Sin cambios"
    }
  ],
  "lastModified": "2026-07-22T19:10:00.120",
  "configurations": [
    {
      "nodes": [
        {
          "negate": false,
          "cpeMatch": [
            {
              "criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "CB67FC73-CF7B-41DB-A5A5-423C53BE93EF",
              "versionEndExcluding": "6.12.75",
              "versionStartIncluding": "6.10"
            },
            {
              "criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "BF463CB7-1F58-4607-B847-77ED23E4B9B7",
              "versionEndExcluding": "6.18.14",
              "versionStartIncluding": "6.13"
            },
            {
              "criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "672A3E79-EC03-479D-8503-361DFBDC8092",
              "versionEndExcluding": "6.19.4",
              "versionStartIncluding": "6.19"
            }
          ],
          "operator": "OR"
        }
      ]
    }
  ],
  "sourceIdentifier": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
}