CyberAlerts is shutting down on June 30th, 2025. Thank you for your support!

CVE-2025-37847: accel/ivpu: Fix deadlock in ivpu_ms_cleanup()

Description

In the Linux kernel, the following vulnerability has been resolved:

accel/ivpu: Fix deadlock in ivpu_ms_cleanup()

Fix deadlock in ivpu_ms_cleanup() by preventing runtime resume after
file_priv->ms_lock is acquired.

During a failure in runtime resume, a cold boot is executed, which
calls ivpu_ms_cleanup_all(). This function calls ivpu_ms_cleanup()
that acquires file_priv->ms_lock and causes the deadlock.

Classification

CVE ID: CVE-2025-37847

Affected Products

Vendor: Linux

Product: Linux

Exploit Prediction Scoring System (EPSS)

EPSS Score: 0.02% (probability of being exploited)

EPSS Percentile: 4.6% (scored less or equal to compared to others)

EPSS Date: 2025-06-07 (when was this score calculated)

References

https://nvd.nist.gov/vuln/detail/CVE-2025-37847
https://git.kernel.org/stable/c/7d12a7d43c7bab9097ba466581d8db702e7908dc
https://git.kernel.org/stable/c/f996ecc789b5dbaaf38b6ec0a1917821789cbd9c
https://git.kernel.org/stable/c/019634f27a16796eab749e8107dae32099945f29
https://git.kernel.org/stable/c/9a6f56762d23a1f3af15e67901493c927caaf882

Timeline