{ "dataType": "CVE_RECORD", "dataVersion": "5.2", "cveMetadata": { "cveId": "CVE-2025-37763", "assignerOrgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67", "state": "PUBLISHED", "assignerShortName": "Linux", "dateReserved": "2025-04-16T04:51:23.938Z", "datePublished": "2025-05-01T13:07:05.042Z", "dateUpdated": "2026-08-05T11:57:24.176Z" }, "containers": { "cna": { "providerMetadata": { "orgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67", "shortName": "Linux", "dateUpdated": "2026-08-05T11:57:24.176Z" }, "descriptions": [ { "lang": "en", "value": "In the Linux kernel, the following vulnerability has been resolved:\n\ndrm/imagination: take paired job reference\n\nFor paired jobs, have the fragment job take a reference on the\ngeometry job, so that the geometry job cannot be freed until\nthe fragment job has finished with it.\n\nThe geometry job structure is accessed when the fragment job is being\nprepared by the GPU scheduler. Taking the reference prevents the\ngeometry job being freed until the fragment job no longer requires it.\n\nFixes a use after free bug detected by KASAN:\n\n[ 124.256386] BUG: KASAN: slab-use-after-free in pvr_queue_prepare_job+0x108/0x868 [powervr]\n[ 124.264893] Read of size 1 at addr ffff0000084cb960 by task kworker/u16:4/63" } ], "metrics": [ { "cvssV3_1": { "version": "3.1", "vectorString": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H", "baseScore": 7.8, "baseSeverity": "HIGH" }, "scenarios": [ { "lang": "en", "value": "AV:L - The vulnerability is reached through the DRM_IOCTL_PVR_SUBMIT_JOBS ioctl on the PowerVR render node (/dev/dri/renderD*), requiring local access to the device file. There is no remote or network-facing path to this code.\nAC:L - The attacker controls both sides of the lifetime bug: they submit the paired geometry/fragment jobs, can make the geometry job complete (and be freed) immediately, and can stall the fragment job's prepare_job indefinitely with an unsignaled syncobj dependency, giving unlimited time to reallocate the freed pvr_job slot with controlled data. The bug also reproduces under ordinary rendering workloads.\nPR:L - SUBMIT_JOBS is flagged DRM_RENDER_ALLOW on a DRIVER_RENDER device, so no DRM master, authentication, or capability is required — only the ability to open the render node, which is granted to every unprivileged graphics client on Android/embedded targets and to normal local users on desktop systems.\nUI:N - The attacker submits their own job pairs and signals their own sync objects; no victim action or interaction is needed at any point.\nS:U - The use-after-free occurs in kernel memory owned by the DRM driver and the impact stays within the kernel's security authority, with no VM, IOMMU, or hypervisor boundary crossed.\nC:H - The freed pvr_job lives in a generic kmalloc cache that the attacker can reallocate with controlled content, after which the code dereferences an attacker-chosen `done_fence` pointer and walks `jfence->queue->timeline_ufo.fw_obj`, yielding a chained arbitrary-read primitive whose results are observable through the firmware sync objects.\nI:H - The same UAF gives an indirect call through `frag_job->base.sched->ops->prepare_job` and lets an attacker-influenced address/value pair be written into the GPU firmware command buffer as a UFO write target, providing control-flow hijack and write primitives from a groomed heap.\nA:H - Even without full exploitation the dangling dereference reliably oopses the kernel (as caught by KASAN), and the WARN_ON paths plus corrupted firmware command streams can wedge the GPU scheduler, crashing the system." } ] } ], "affected": [ { "product": "Linux", "vendor": "Linux", "defaultStatus": "unaffected", "repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git", "programFiles": [ "drivers/gpu/drm/imagination/pvr_job.c", "drivers/gpu/drm/imagination/pvr_queue.c" ], "versions": [ { "version": "eaf01ee5ba28b97f96a3d3eec4c5fbfb37ee4cde", "lessThan": "c90b95e12eb88d23740e5ea2c43d71675d17ac8d", "status": "affected", "versionType": "git" }, { "version": "eaf01ee5ba28b97f96a3d3eec4c5fbfb37ee4cde", "lessThan": "b5a6f97a78e2fc008fd6503b7040cb7e1120b873", "status": "affected", "versionType": "git" }, { "version": "eaf01ee5ba28b97f96a3d3eec4c5fbfb37ee4cde", "lessThan": "4ba2abe154ef68f9612eee9d6fbfe53a1736b064", "status": "affected", "versionType": "git" } ] }, { "product": "Linux", "vendor": "Linux", "defaultStatus": "affected", "repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git", "programFiles": [ "drivers/gpu/drm/imagination/pvr_job.c", "drivers/gpu/drm/imagination/pvr_queue.c" ], "versions": [ { "version": "6.8", "status": "affected" }, { "version": "0", "lessThan": "6.8", "status": "unaffected", "versionType": "semver" }, { "version": "6.12.25", "lessThanOrEqual": "6.12.*", "status": "unaffected", "versionType": "semver" }, { "version": "6.14.4", "lessThanOrEqual": "6.14.*", "status": "unaffected", "versionType": "semver" }, { "version": "6.15", "lessThanOrEqual": "*", "status": "unaffected", "versionType": "original_commit_for_fix" } ] } ], "cpeApplicability": [ { "nodes": [ { "operator": "OR", "negate": false, "cpeMatch": [ { "vulnerable": true, "criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*", "versionStartIncluding": "6.8", "versionEndExcluding": "6.12.25" }, { "vulnerable": true, "criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*", "versionStartIncluding": "6.8", "versionEndExcluding": "6.14.4" }, { "vulnerable": true, "criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*", "versionStartIncluding": "6.8", "versionEndExcluding": "6.15" } ] } ] } ], "references": [ { "url": "https://git.kernel.org/stable/c/c90b95e12eb88d23740e5ea2c43d71675d17ac8d" }, { "url": "https://git.kernel.org/stable/c/b5a6f97a78e2fc008fd6503b7040cb7e1120b873" }, { "url": "https://git.kernel.org/stable/c/4ba2abe154ef68f9612eee9d6fbfe53a1736b064" } ], "title": "drm/imagination: take paired job reference", "x_generator": { "engine": "bippy-1.2.0" } } } }