{"id":"DEBIAN-CVE-2025-38520","details":"In the Linux kernel, the following vulnerability has been resolved:  drm/amdkfd: Don't call mmput from MMU notifier callback  If the process is exiting, the mmput inside mmu notifier callback from compactd or fork or numa balancing could release the last reference of mm struct to call exit_mmap and free_pgtable, this triggers deadlock with below backtrace.  The deadlock will leak kfd process as mmu notifier release is not called and cause VRAM leaking.  The fix is to take mm reference mmget_non_zero when adding prange to the deferred list to pair with mmput in deferred list work.  If prange split and add into pchild list, the pchild work_item.mm is not used, so remove the mm parameter from svm_range_unmap_split and svm_range_add_child.  The backtrace of hung task:   INFO: task python:348105 blocked for more than 64512 seconds.  Call Trace:   __schedule+0x1c3/0x550   schedule+0x46/0xb0   rwsem_down_write_slowpath+0x24b/0x4c0   unlink_anon_vmas+0xb1/0x1c0   free_pgtables+0xa9/0x130   exit_mmap+0xbc/0x1a0   mmput+0x5a/0x140   svm_range_cpu_invalidate_pagetables+0x2b/0x40 [amdgpu]   mn_itree_invalidate+0x72/0xc0   __mmu_notifier_invalidate_range_start+0x48/0x60   try_to_unmap_one+0x10fa/0x1400   rmap_walk_anon+0x196/0x460   try_to_unmap+0xbb/0x210   migrate_page_unmap+0x54d/0x7e0   migrate_pages_batch+0x1c3/0xae0   migrate_pages_sync+0x98/0x240   migrate_pages+0x25c/0x520   compact_zone+0x29d/0x590   compact_zone_order+0xb6/0xf0   try_to_compact_pages+0xbe/0x220   __alloc_pages_direct_compact+0x96/0x1a0   __alloc_pages_slowpath+0x410/0x930   __alloc_pages_nodemask+0x3a9/0x3e0   do_huge_pmd_anonymous_page+0xd7/0x3e0   __handle_mm_fault+0x5e3/0x5f0   handle_mm_fault+0xf7/0x2e0   hmm_vma_fault.isra.0+0x4d/0xa0   walk_pmd_range.isra.0+0xa8/0x310   walk_pud_range+0x167/0x240   walk_pgd_range+0x55/0x100   __walk_page_range+0x87/0x90   walk_page_range+0xf6/0x160   hmm_range_fault+0x4f/0x90   amdgpu_hmm_range_get_pages+0x123/0x230 [amdgpu]   amdgpu_ttm_tt_get_user_pages+0xb1/0x150 [amdgpu]   init_user_pages+0xb1/0x2a0 [amdgpu]   amdgpu_amdkfd_gpuvm_alloc_memory_of_gpu+0x543/0x7d0 [amdgpu]   kfd_ioctl_alloc_memory_of_gpu+0x24c/0x4e0 [amdgpu]   kfd_ioctl+0x29d/0x500 [amdgpu]  (cherry picked from commit a29e067bd38946f752b0ef855f3dfff87e77bec7)","modified":"2026-09-01T16:06:14.715599014Z","published":"2025-08-16T11:15:45.283Z","upstream":["CVE-2025-38520"],"references":[{"type":"ADVISORY","url":"https://security-tracker.debian.org/tracker/CVE-2025-38520"}],"affected":[{"package":{"name":"linux","ecosystem":"Debian:12","purl":"pkg:deb/debian/linux?arch=source&distro=bookworm"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"6.1.148-1"}]}],"versions":["6.1.106-1","6.1.106-2","6.1.106-3","6.1.112-1","6.1.115-1","6.1.119-1","6.1.123-1","6.1.124-1","6.1.128-1","6.1.129-1","6.1.133-1","6.1.135-1","6.1.137-1","6.1.139-1","6.1.140-1","6.1.147-1","6.1.27-1","6.1.37-1","6.1.38-1","6.1.38-2","6.1.38-2~bpo11+1","6.1.38-3","6.1.38-4","6.1.38-4~bpo11+1","6.1.52-1","6.1.55-1","6.1.55-1~bpo11+1","6.1.64-1","6.1.66-1","6.1.67-1","6.1.69-1","6.1.69-1~bpo11+1","6.1.76-1","6.1.76-1~bpo11+1","6.1.82-1","6.1.85-1","6.1.90-1","6.1.90-1~bpo11+1","6.1.94-1","6.1.94-1~bpo11+1","6.1.98-1","6.1.99-1"],"ecosystem_specific":{"urgency":"not yet assigned"},"database_specific":{"source":"https://storage.googleapis.com/osv-test-debian-osv/debian-cve-osv/DEBIAN-CVE-2025-38520.json"}},{"package":{"name":"linux","ecosystem":"Debian:13","purl":"pkg:deb/debian/linux?arch=source&distro=trixie"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"6.12.41-1"}]}],"versions":["6.12.38-1"],"ecosystem_specific":{"urgency":"not yet assigned"},"database_specific":{"source":"https://storage.googleapis.com/osv-test-debian-osv/debian-cve-osv/DEBIAN-CVE-2025-38520.json"}},{"package":{"name":"linux","ecosystem":"Debian:14","purl":"pkg:deb/debian/linux?arch=source&distro=forky"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"6.16.3-1"}]}],"versions":["6.12.100-1","6.12.101-1","6.12.105-1","6.12.107-1","6.12.38-1","6.12.41-1","6.12.43-1","6.12.43-1~bpo12+1","6.12.48-1","6.12.57-1","6.12.57-1~bpo12+1","6.12.63-1","6.12.63-1~bpo12+1","6.12.69-1","6.12.69-1~bpo12+1","6.12.73-1","6.12.73-1~bpo12+1","6.12.74-1","6.12.74-2","6.12.74-2~bpo12+1","6.12.85-1","6.12.85-1~bpo12+1","6.12.86-1","6.12.86-1~bpo12+1","6.12.88-1","6.12.88-1~bpo12+1","6.12.90-1","6.12.90-1~bpo12+1","6.12.90-2","6.12.90-2~bpo12+1","6.12.94-1","6.12.94-1~bpo12+1","6.12.95-1","6.12.95-1~bpo12+1","6.12.96-1","6.13.10-1~exp1","6.13.11-1~exp1","6.13.2-1~exp1","6.13.3-1~exp1","6.13.4-1~exp1","6.13.5-1~exp1","6.13.6-1~exp1","6.13.7-1~exp1","6.13.8-1~exp1","6.13.9-1~exp1","6.13~rc6-1~exp1","6.13~rc7-1~exp1","6.14.3-1~exp1","6.14.5-1~exp1","6.14.6-1~exp1","6.15-1~exp1","6.15.1-1~exp1","6.15.2-1~exp1","6.15.3-1~exp1","6.15.4-1~exp1","6.15.5-1~exp1","6.15.6-1~exp1","6.15~rc7-1~exp1","6.16-1~exp1","6.16.1-1~exp1","6.16.3-1~bpo13+1","6.16~rc7-1~exp1"],"ecosystem_specific":{"urgency":"not yet assigned"},"database_specific":{"source":"https://storage.googleapis.com/osv-test-debian-osv/debian-cve-osv/DEBIAN-CVE-2025-38520.json"}}],"schema_version":"1.9.0","severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H"}]}