drm/sched: Increment job count before swapping tail spsc queue
3Vexday Risk Score
No sign of exploitation. No public exploitation artifact known so far.
ssvc Trackepss 0.2%
exploitation probability
0.2%top 95% of all CVEs
observed exploitation
nono source reports it
In the Linux kernel, the following vulnerability has been resolved:
drm/sched: Increment job count before swapping tail spsc queue
A small race exists between spsc_queue_push and the run-job worker, in
which spsc_queue_push may return not-first while the run-job worker has
already idled due to the job count being zero. If this race occurs, job
scheduling stops, leading to hangs while waiting on the job’s DMA
fences.
Seal this race by incrementing the job count before appending to the
SPSC queue.
This race was observed on a drm-tip 6.16-rc1 build with the Xe driver in
an SVM test case.
Affected products
Linux · LinuxReferences
https://git.kernel.org/stable/c/549a9c78c3ea6807d0dc4162a4f5ba59f217d5a0https://git.kernel.org/stable/c/8af39ec5cf2be522c8eb43a3d8005ed59e4daaeehttps://git.kernel.org/stable/c/c64f5310530baf75328292f9b9f3f2961d185183https://git.kernel.org/stable/c/e2d6547dc8b9b332f9bc00875197287a6a4db65ahttps://git.kernel.org/stable/c/e62f51d0ec8a9baf324caf9a564f8e318d36a551https://git.kernel.org/stable/c/ef58a95457466849fa7b31fd3953801a5af0f58bhttps://git.kernel.org/stable/c/ef841f8e4e1ff67817ca899bedc5ebb00847c0a7https://git.kernel.org/stable/c/f9a4f28a4fc4ee453a92a9abbe36e26224d17749https://lists.debian.org/debian-lts-announce/2025/10/msg00007.htmlhttps://lists.debian.org/debian-lts-announce/2025/10/msg00008.html