Executive brief
A vulnerability was identified in the Linux kernel's Intel Xe graphics driver. The issue occurs when the system fails to properly handle memory during certain graphics operations, potentially allowing a local user to cause a system crash or gain unauthorized access to system memory. This could impact the stability and security of systems using Intel graphics hardware.
Technical details
A double-free vulnerability (CWE-415) exists in the Intel Xe DRM driver (drivers/gpu/drm/xe/xe_vm.c) within the Linux kernel. The issue resides in the xe_vm_bind_ioctl function where, if an argument check fails during an array bind operation, the bind_ops pointer is freed but not set to NULL. This leads to a subsequent second free of the same memory address during error cleanup. A local attacker with access to the DRM IOCTLs could exploit this to cause a kernel panic (DoS) or potentially achieve arbitrary code execution. The vulnerability was introduced in version 6.15 and is resolved in version 6.16.4 and later.
Affected products
- Linux Linux Kernel 6.15 to 6.16.3
Timeline
- 2025-08-13: disclosed: Initial patch submitted by Intel developers
- 2025-08-28: patched: Patch committed to stable kernel tree
- 2025-09-05: advisory: CVE-2025-38731 published