Junglewise Threat Intelligence

CVE-2026-63863: Linux Kernel unbalanced unlock in drm_gpusvm_scan_mm

CVE-2026-63863 · Severity: info · Published 2026-07-19

Technologies: Linux. Vendors: Linux.

Executive brief

A synchronization error was identified in the Linux kernel's graphics subsystem (DRM) specifically affecting GPU Shared Virtual Memory (GPUSVM). This flaw could cause the system to attempt to release a lock that was never acquired, potentially leading to system instability or crashes. This affects systems using specific GPU memory management features in newer Linux kernel versions.

Technical details

An unbalanced lock/unlock vulnerability existed in the drm_gpusvm_scan_mm() function within the Linux kernel's DRM GPUSVM helper. The root cause was a 'goto' statement jumping to an error label (err_free) that executed an unlock operation before the corresponding lock had been acquired. This logic error triggered kernel warnings and could lead to undefined behavior or deadlocks in the GPU memory management subsystem. The issue was resolved by adjusting the control flow to ensure the unlock operation is only called when a lock is held. Patches have been applied to the stable kernel branches.

Affected products

  • Linux Linux 7.0 to 7.0.10

Timeline

  • 2026-02-09: disclosed: Initial patch authored
  • 2026-07-19: advisory: CVE published

References