In the Linux kernel, the following vulnerability has been resolved:
drm/nouveau: Fix WARN_ON in nouveau_fence_context_kill()
Nouveau is mostly designed in a way that it's expected that fences only
ever get signaled through nouveau_fence_signal(). However, in at least
one other place, nouveau_fence_done(), can signal fences, too. If that
happens (race) a signaled fence remains in the pending list for a while,
until it gets removed by nouveau_fence_update().
Should nouveau_fence_context_kill() run in the meantime, this would be
a bug because the function would attempt to set an error code on an
already signaled fence.
Have nouveau_fence_context_kill() check for a fence being signaled.
CVE ID: CVE-2025-37930
Vendor: Linux
Product: Linux
EPSS Score: 0.07% (probability of being exploited)
EPSS Percentile: 21.81% (scored less or equal to compared to others)
EPSS Date: 2025-06-18 (when was this score calculated)