Executive brief
A vulnerability in the Linux kernel's memory management system could allow a local user to cause a system crash. The issue occurs when the system attempts to record diagnostic information about shared memory buffers while another process is simultaneously closing them. This can lead to a 'use-after-free' condition, potentially impacting system stability and availability.
Technical details
A use-after-free (UAF) vulnerability exists in the dma_buf_fd() function within the Linux kernel's dma-buf implementation. The root cause is a race condition where FD_ADD() makes a file descriptor live in the descriptor table before the DMA_BUF_TRACE() tracepoint executes. A concurrent thread sharing the file descriptor table can call close(), dropping the final reference and freeing the dma_buf structure before the tracepoint attempts to access it. This results in a slab-use-after-free when the tracepoint dereferences the dmabuf to acquire name_lock. The fix involves splitting the operation into get_unused_fd_flags() and fd_install(), placing the tracepoint between them to ensure the buffer remains valid.
Affected products
- Linux Linux Kernel 7.0 to 7.0.11
Timeline
- 2026-05-23: disclosed: Initial patch submitted by David Carlier
- 2026-07-19: advisory: CVE-2026-63910 published