Junglewise Threat Intelligence

CVE-2026-63910: Linux Kernel use-after-free in dma-buf dma_buf_fd tracepoint

CVE-2026-63910 · Severity: info · CVSS 5.5 · Published 2026-07-19

Technologies: Linux Kernel. Vendors: Linux.

Executive brief

A vulnerability in the Linux kernel's memory management system could allow a local user to cause a system crash. The issue occurs when the system attempts to record diagnostic information about shared memory buffers while another process is simultaneously closing them. This can lead to a 'use-after-free' condition, potentially impacting system stability and availability.

Technical details

A use-after-free (UAF) vulnerability exists in the dma_buf_fd() function within the Linux kernel's dma-buf implementation. The root cause is a race condition where FD_ADD() makes a file descriptor live in the descriptor table before the DMA_BUF_TRACE() tracepoint executes. A concurrent thread sharing the file descriptor table can call close(), dropping the final reference and freeing the dma_buf structure before the tracepoint attempts to access it. This results in a slab-use-after-free when the tracepoint dereferences the dmabuf to acquire name_lock. The fix involves splitting the operation into get_unused_fd_flags() and fd_install(), placing the tracepoint between them to ensure the buffer remains valid.

Affected products

  • Linux Linux Kernel 7.0 to 7.0.11

Timeline

  • 2026-05-23: disclosed: Initial patch submitted by David Carlier
  • 2026-07-19: advisory: CVE-2026-63910 published

References

Related threats