Executive brief
A vulnerability was identified in the Linux kernel's Intel Xe graphics driver. The issue occurs when the system unbinds a graphics device while a background diagnostic task is still running, potentially leading to a system crash or unpredictable behavior. This could allow a local user with basic access to compromise the stability or security of the operating system.
Technical details
A race condition exists in the Intel Xe graphics driver (drm/xe) within the Linux kernel. The vulnerability is caused by a lack of synchronization between the 'Dead CT' worker thread and the device unbinding process in 'xe_guc_ct.c'. If a device is unbound while the worker is active, the worker may attempt to access memory or resources that have already been freed by the unbind operation, leading to a use-after-free. This requires local access and can result in a kernel panic or privilege escalation. The fix introduces 'cancel_work_sync' to ensure the worker completes or is cancelled before resources are released.
Affected products
- Linux Linux Kernel 6.12.37 to 6.12.59, 6.13, 6.17.9
Timeline
- 2025-12-16: advisory: CVE-2025-68207 published by NVD
- 2025-11-24: patched: Fix committed to stable kernel branches