CVE-2025-38703: drm/xe: Make dma-fences compliant with the safe access rules

Published Sep 4, 2025
·
Updated

In the Linux kernel, the following vulnerability has been resolved:

drm/xe: Make dma-fences compliant with the safe access rules

Xe can free some of the data pointed to by the dma-fences it exports. Most notably the timeline name can get freed if userspace closes the associated submit queue. At the same time the fence could have been exported to a third party (for example a syncfence fd) which will then cause an use- after-free on subsequent access.

To make this safe we need to make the driver compliant with the newly documented dma-fence rules. Driver has to ensure a RCU grace period between signalling a fence and freeing any data pointed to by said fence.

For the timeline name we simply make the queue be freed via kfreercu and for the shared lock associated with multiple queues we add a RCU grace period before freeing the per GT structure holding the lock.

Affected Software

4 affected components
Linux Linux kernel
Linux Linux kernel>=6.8<6.12.43
Linux Linux kernel>=6.13<6.15.11
Linux Linux kernel>=6.16<6.16.2

Event History

Sep 4, 2025
CVE Published
via MITRE·03:32 PM
Data Sourced
via MITRE·03:32 PM
DescriptionSeverity
Data Sourced
via Red Hat·04:01 PM
DescriptionSeverityAffected Software
Data Sourced
via NVD·04:15 PM
RemedyDescriptionSeverityWeaknessAffected Software

Frequently Asked Questions

1

What is the severity of CVE-2025-38703?

CVE-2025-38703 is categorized as a medium severity vulnerability in the Linux kernel.

2

How do I fix CVE-2025-38703?

To fix CVE-2025-38703, update your Linux kernel to the latest stable version that includes the security patch.

3

What are the potential impacts of CVE-2025-38703?

CVE-2025-38703 may lead to denial of service if the dma-fences are improperly managed, allowing for potential data corruption.

4

Which software is affected by CVE-2025-38703?

CVE-2025-38703 affects the Linux kernel, particularly those utilizing the Xe graphics driver.

5

Is CVE-2025-38703 being actively exploited?

There have been no reported active exploits for CVE-2025-38703 as of the latest updates.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203