Junglewise Threat Intelligence

CVE-2026-53290: Linux Kernel Intel Xe driver use-after-free in xe_eu_stall_stream_close

CVE-2026-53290 · Severity: info · Published 2026-06-26

Technologies: Linux Kernel. Vendors: Linux.

Executive brief

A vulnerability was identified in the Linux kernel's Intel Xe graphics driver. The issue occurs when closing a specific data stream, where the system might prematurely release memory associated with the graphics device while it is still being used. This could lead to system instability or a crash, potentially allowing a local user to disrupt operations.

Technical details

A use-after-free vulnerability exists in the xe_eu_stall_stream_close() function within the Intel Xe graphics driver (drivers/gpu/drm/xe/xe_eu_stall.c). The root cause is an incorrect sequence where drm_dev_put() is called before the stream is disabled and its resources are freed. If drm_dev_put() drops the final reference, the device structures are deallocated while subsequent cleanup code still attempts to access them. This is a local vulnerability that can be triggered during the closing of an EU stall stream. Patches have been released for various stable branches including 6.18.x and 7.0.x.

Affected products

  • Linux Linux Kernel 6.15 to 6.18.33, 7.0.10, 7.1

Timeline

  • 2026-04-15: other: Initial patch authored
  • 2026-06-26: advisory: CVE published by NVD

References

Related threats