Executive brief
A vulnerability exists in the Linux kernel's Intel Xe graphics driver that could allow a local user to crash the system or potentially execute unauthorized code. The issue occurs when the system prematurely deletes memory associated with graphics synchronization tasks while that memory is still being accessed by other parts of the system. This could lead to system instability or a security breach if an attacker can manipulate the freed memory.
Technical details
A use-after-free (UAF) vulnerability exists in the drm/xe driver due to non-compliance with dma-fence safe access rules. Specifically, the driver could free data pointed to by exported dma-fences, such as the timeline name, when userspace closes an associated submit queue. If the fence was exported to a third party (e.g., via a sync_fence file descriptor), subsequent access results in a UAF. The fix implements RCU-based freeing (kfree_rcu) for the queue and adds RCU grace periods before freeing structures holding shared locks to ensure all references are cleared before memory reclamation.
Affected products
- Linux Linux Kernel 6.8 to 6.12.42, 6.13 to 6.15.10, 6.16 to 6.16.1
Timeline
- 2025-06-10: disclosed: Initial patch authored
- 2025-08-20: patched: Patches committed to stable branches
- 2025-09-04: advisory: CVE published