{"id":"DEBIAN-CVE-2025-37907","details":"In the Linux kernel, the following vulnerability has been resolved:  accel/ivpu: Fix locking order in ivpu_job_submit  Fix deadlock in job submission and abort handling. When a thread aborts currently executing jobs due to a fault, it first locks the global lock protecting submitted_jobs (#1).  After the last job is destroyed, it proceeds to release the related context and locks file_priv (#2). Meanwhile, in the job submission thread, the file_priv lock (#2) is taken first, and then the submitted_jobs lock (#1) is obtained when a job is added to the submitted jobs list.         CPU0                            CPU1        ----                    \t       ----   (for example due to a fault)         (jobs submissions keep coming)    lock(&vdev-\u003esubmitted_jobs_lock) #1   ivpu_jobs_abort_all()   job_destroy()                                       lock(&file_priv-\u003elock)           #2                                       lock(&vdev-\u003esubmitted_jobs_lock) #1   file_priv_release()   lock(&vdev-\u003econtext_list_lock)   lock(&file_priv-\u003elock)           #2  This order of locking causes a deadlock. To resolve this issue, change the order of locking in ivpu_job_submit().","modified":"2026-08-27T23:05:28.950211092Z","published":"2025-05-20T16:15:27.177Z","upstream":["CVE-2025-37907"],"references":[{"type":"ADVISORY","url":"https://security-tracker.debian.org/tracker/CVE-2025-37907"}],"affected":[{"package":{"name":"linux","ecosystem":"Debian:13","purl":"pkg:deb/debian/linux?arch=source&distro=trixie"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"6.12.29-1"}]}],"ecosystem_specific":{"urgency":"not yet assigned"},"database_specific":{"source":"https://storage.googleapis.com/osv-test-debian-osv/debian-cve-osv/DEBIAN-CVE-2025-37907.json"}},{"package":{"name":"linux","ecosystem":"Debian:14","purl":"pkg:deb/debian/linux?arch=source&distro=forky"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"6.12.29-1"}]}],"ecosystem_specific":{"urgency":"not yet assigned"},"database_specific":{"source":"https://storage.googleapis.com/osv-test-debian-osv/debian-cve-osv/DEBIAN-CVE-2025-37907.json"}}],"schema_version":"1.9.0","severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H"}]}