CVE-2025-38521

I

n the Linux kernel, the following vulnerability has been resolved: drm/imagination: Fix kernel crash when hard resetting the GPU The GPU hard reset sequence calls pm_runtime_force_suspend() and pm_runtime_force_resume(), which according to their documentation should only be used during system-wide PM transitions to sleep states. The main issue though is that depending on some internal runtime PM state as seen by pm_runtime_force_suspend() (whether the usage count is <= 1), pm_runtime_force_resume() might not resume the device unless needed. If that happens, the runtime PM resume callback pvr_power_device_resume() is not called, the GPU clocks are not re-enabled, and the kernel crashes on the next attempt to access GPU registers as part of the power-on sequence. Replace calls to pm_runtime_force_suspend() and pm_runtime_force_resume() with direct calls to the driver's runtime PM callbacks, pvr_power_device_suspend() and pvr_power_device_resume(), to ensure clocks are re-enabled and avoid the kernel crash.

Configurations

Configuration 1 (hide)

OR cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*
cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*
cpe:2.3:o:linux:linux_kernel:6.16:rc1:*:*:*:*:*:*
cpe:2.3:o:linux:linux_kernel:6.16:rc2:*:*:*:*:*:*
cpe:2.3:o:linux:linux_kernel:6.16:rc3:*:*:*:*:*:*
cpe:2.3:o:linux:linux_kernel:6.16:rc4:*:*:*:*:*:*
cpe:2.3:o:linux:linux_kernel:6.16:rc5:*:*:*:*:*:*

History

22 Jan 2026, 18:38

Type Values Removed Values Added
CVSS v2 : unknown
v3 : unknown
v2 : unknown
v3 : 7.1
CWE CWE-668
References () https://git.kernel.org/stable/c/9f852d301f642223c4798f3c13ba15e91165d078 - () https://git.kernel.org/stable/c/9f852d301f642223c4798f3c13ba15e91165d078 - Patch
References () https://git.kernel.org/stable/c/d38376b3ee48d073c64e75e150510d7e6b4b04f7 - () https://git.kernel.org/stable/c/d38376b3ee48d073c64e75e150510d7e6b4b04f7 - Patch
References () https://git.kernel.org/stable/c/e066cc6e0f094ca2120f1928d126d56f686cd73e - () https://git.kernel.org/stable/c/e066cc6e0f094ca2120f1928d126d56f686cd73e - Patch
First Time Linux linux Kernel
Linux
CPE cpe:2.3:o:linux:linux_kernel:6.16:rc5:*:*:*:*:*:*
cpe:2.3:o:linux:linux_kernel:6.16:rc4:*:*:*:*:*:*
cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*
cpe:2.3:o:linux:linux_kernel:6.16:rc3:*:*:*:*:*:*
cpe:2.3:o:linux:linux_kernel:6.16:rc1:*:*:*:*:*:*
cpe:2.3:o:linux:linux_kernel:6.16:rc2:*:*:*:*:*:*

18 Aug 2025, 20:16

Type Values Removed Values Added
New CVE

Information

Published : 2025-08-16 11:15

Updated : 2026-01-22 18:38


NVD link : CVE-2025-38521

Mitre link : CVE-2025-38521

CVE.ORG link : CVE-2025-38521


JSON object : View

Products Affected
CWE
CWE-668

Exposure of Resource to Wrong Sphere