Executive brief
A vulnerability was identified in the Linux kernel's Intel graphics driver (i915) that could lead to a system crash or unpredictable behavior. The issue occurs when the system attempts to clear out memory used by the graphics card under heavy load, potentially accessing memory that has already been freed or replaced. This could allow a local user to cause a denial of service (system crash) or potentially gain unauthorized access to system memory.
Technical details
A use-after-free (UAF) vulnerability exists in the i915_ttm_purge function within the Linux kernel's DRM subsystem. The root cause is a race condition or improper pointer management where a pointer to an i915 TTM page vector container is captured before a call to ttm_bo_validate(). If ttm_bo_validate() replaces the container instance (e.g., during eviction under heavy memory pressure), the previously captured pointer becomes stale. Subsequent dereferencing of this pointer, specifically a file pointer field, results in a general protection fault. The fix involves re-capturing the pointer only after potential replacement operations have concluded. This issue primarily affects Intel DG2 (Discrete Graphics) platforms.
Affected products
- Linux Linux kernel v5.17+
Timeline
- 2026-05-08: patched: Initial patch submitted by Janusz Krzysztofik
- 2026-07-19: advisory: CVE-2026-63884 published in NVD
References
- https://git.kernel.org/stable/c/073bcbc95e9648c976da1654c7590a8d6ee12c2d
- https://git.kernel.org/stable/c/28b22dbaf407598cb3bb1d2c586a6f8018690ac2
- https://git.kernel.org/stable/c/5c4063c87a619e4df954c179d24628636f5db15f
- https://git.kernel.org/stable/c/a29654d451bbffe63d584a4cf64ad0efce6bcf1c
- https://git.kernel.org/stable/c/c9ae7e7e3bc98615364313b08d7acea5239ded0b
- https://git.kernel.org/stable/c/df73f3bc731af1c39ac5405bc59c4e7c6f8e9117