Executive brief
A vulnerability in the Linux kernel's Panthor DRM driver could allow a local attacker to crash the system or potentially execute unauthorized code. The issue occurs during the creation of graphics processing groups, where a race condition allows a malicious program to delete a group while it is still being initialized. This could lead to system instability or a security breach by manipulating memory that has already been freed.
Technical details
A use-after-free (UAF) vulnerability exists in the GROUP_CREATE ioctl of the Panthor DRM driver (drivers/gpu/drm/panthor/panthor_sched.c). The root cause is a race condition where a group pointer is stored in an Xarray before initialization is complete, allowing a concurrent GROUP_DESTROY ioctl call from another thread to free the group while the creation routine still holds a pointer to it. An attacker can exploit this by guessing the group handle and triggering a destroy operation during the creation window. The fix introduces a 'GROUP_REGISTERED' mark in the Xarray, ensuring that groups cannot be accessed or destroyed until they are fully initialized and marked. Patches are available in stable kernel versions 6.17.13, 6.18.2, and 6.19.
Affected products
- Linux Linux 6.10 to 6.17.12, 6.18.1
Timeline
- 2025-11-27: other: Patch submitted by developer
- 2025-12-24: advisory: CVE published