Executive brief
A vulnerability was identified in the Linux kernel's Radeon graphics driver, which manages how the operating system communicates with AMD/Radeon video cards. A technical error in how the system handles memory during hardware setup could cause the system to crash or 'explode' if the driver fails to load correctly. This could lead to a loss of system availability or potentially allow an attacker to gain unauthorized control over the system.
Technical details
A double-free vulnerability exists in the Linux kernel's Radeon DRM driver (drivers/gpu/drm/radeon/radeon_kms.c). The issue stems from the driver manually calling kfree() on the 'rdev' structure, which is already managed by the devres (device resource management) framework via devm_drm_dev_alloc(). If a driver probe fails, both the manual kfree() and the automatic devres cleanup attempt to release the same memory, leading to a kernel crash or potential memory corruption. This is a local vulnerability requiring low privileges. Patches have been released in various stable kernel branches including 6.12.58 and 6.17.8.
Affected products
- Linux Linux Kernel 6.12, 6.17, 6.18
Timeline
- 2025-12-16: advisory: CVE published by kernel.org
- 2025-10-28: patched: Initial fix committed to the Linux kernel tree