Junglewise Threat Intelligence

CVE-2025-68314: Linux Kernel drm/msm use-after-free in vm-bind path

CVE-2025-68314 · Severity: high · CVSS 8.8 · Published 2025-12-16

Technologies: Linux Kernel. Vendors: Linux.

Executive brief

A vulnerability in the Linux kernel's graphics driver for Qualcomm Adreno GPUs could allow a local user to cause system instability or potentially gain unauthorized access. The issue occurs because the system may prematurely free memory resources while they are still being used by the graphics hardware. This can lead to system crashes or unpredictable behavior when closing certain graphics-intensive applications.

Technical details

A vulnerability in the drm/msm driver (specifically within msm_gem_submit.c) stems from the 'last_fence' synchronization primitive not being correctly updated in the vm-bind path. In vm_bind contexts, the kernel failed to wait for pending GPU work to complete before closing the context. This results in a use-after-free or memory fault because resources are freed while the hardware is still accessing them. The fix involves moving the last_fence update logic to ensure it is always tracked in the vm-bind path. This is a local vulnerability requiring low privileges, but it carries a high impact on system availability and integrity due to its position in the kernel.

Affected products

  • Linux Linux Kernel 6.17 to 6.17.7, 6.18+

Timeline

  • 2025-10-11: patched: Initial fix authored by Anna Maniscalco
  • 2025-12-16: disclosed: CVE published by kernel.org

References

Related threats