CVE-2025-40163

Source
https://cve.org/CVERecord?id=CVE-2025-40163
Import Source
https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2025-40163.json
JSON Data
https://api.osv.dev/v1/vulns/CVE-2025-40163
Downstream
Published
2025-11-12T10:26:23.199Z
Modified
2025-12-05T10:21:57.666697Z
Summary
sched/deadline: Stop dl_server before CPU goes offline
Details

In the Linux kernel, the following vulnerability has been resolved:

sched/deadline: Stop dl_server before CPU goes offline

IBM CI tool reported kernel warning[1] when running a CPU removal operation through drmgr[2]. i.e "drmgr -c cpu -r -q 1"

WARNING: CPU: 0 PID: 0 at kernel/sched/cpudeadline.c:219 cpudlset+0x58/0x170 NIP [c0000000002b6ed8] cpudlset+0x58/0x170 LR [c0000000002b7cb8] dlservertimer+0x168/0x2a0 Call Trace: [c000000002c2f8c0] initstack+0x78c0/0x8000 (unreliable) [c0000000002b7cb8] dlservertimer+0x168/0x2a0 [c00000000034df84] _hrtimerrunqueues+0x1a4/0x390 [c00000000034f624] hrtimerinterrupt+0x124/0x300 [c00000000002a230] timerinterrupt+0x140/0x320

Git bisects to: commit 4ae8d9aa9f9d ("sched/deadline: Fix dl_server getting stuck")

This happens since: - dlserver hrtimer gets enqueued close to cpu offline, when kthreadpark enqueues a fair task. - CPU goes offline and drmgr removes it from cpupresentmask. - hrtimer fires and warning is hit.

Fix it by stopping the dl_server before CPU is marked dead.

[sshegde: wrote the changelog and tested it]

Database specific
{
    "cna_assigner": "Linux",
    "osv_generated_from": "https://github.com/CVEProject/cvelistV5/tree/main/cves/2025/40xxx/CVE-2025-40163.json"
}
References

Affected packages

Git / git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git

Affected ranges

Type
GIT
Repo
https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git
Events
Introduced
4ae8d9aa9f9dc7137ea5e564d79c5aa5af1bc45c
Fixed
ab6c0f158508bb16d483add70b73a73f95651c33
Fixed
ee6e44dfe6e50b4a5df853d933a96bdff5309e6e

Affected versions

v6.*
v6.17
v6.17-rc7
v6.17.1
v6.17.2
v6.17.3
v6.17.4
v6.18-rc1

Database specific

source
"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2025-40163.json"

Linux / Kernel

Package

Name
Kernel

Affected ranges

Type
ECOSYSTEM
Events
Introduced
6.17.0
Fixed
6.17.5

Database specific

source
"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2025-40163.json"