Junglewise Threat Intelligence

CVE-2025-39740: Linux Kernel Intel Xe DRM driver use-after-free in xe_migrate

CVE-2025-39740 · Severity: high · CVSS 7.8 · Published 2025-09-11

Technologies: Linux Kernel. Vendors: Linux.

Executive brief

A vulnerability was identified in the Linux kernel's Intel Xe graphics driver, which manages how data is moved between system memory and video memory. A flaw in how the system handles errors during these data transfers could allow a local user to trigger a system crash or potentially gain unauthorized access to sensitive information. This issue primarily affects systems using Intel Xe graphics hardware running specific versions of the Linux kernel.

Technical details

A use-after-free (UAF) vulnerability exists in the `xe_migrate_access_memory` function within `drivers/gpu/drm/xe/xe_migrate.c` of the Linux kernel. The root cause is an incorrect reference counting sequence where `dma_fence_put()` was called before a potential `dma_fence_wait()` in the error path. If an error occurs during memory migration, the kernel might attempt to wait on a synchronization object (fence) that has already been released, leading to a UAF condition. This is reachable by a local user with access to the DRM device. The issue has been resolved by reordering the operations to ensure the fence is only released after all wait operations are complete. Patches are available in stable kernel releases 6.16.2 and later.

Affected products

  • Linux Linux Kernel 6.16 to 6.16.2

Timeline

  • 2025-09-11: disclosed
  • 2025-08-20: patched: Patched in stable branch 6.16.2

References

Related threats