Executive brief
A vulnerability was identified in the Linux kernel's Intel Xe graphics driver. The issue occurs during the initialization of the Graphics Security Controller (GSC), where a memory management error could lead to a system crash or instability. This typically happens when the driver fails to load correctly, causing it to attempt to release the same memory resource twice.
Technical details
A double-free vulnerability exists in the `xe_gsc_init_post_hwconfig()` function within the `drivers/gpu/drm/xe/xe_gsc.c` component of the Linux kernel. The root cause is an explicit call to `xe_bo_unpin_map_no_vm()` in an error handling path for a Buffer Object (BO) that was already managed by the `devm` (device manager) framework. When a probe failure occurs, the `devm` cleanup mechanism attempts to free the resource a second time. This flaw can be triggered locally during driver initialization or hardware probing. The issue has been resolved by removing the redundant explicit free call, allowing the kernel's managed resource framework to handle the cleanup exclusively.
Affected products
- Linux Linux 6.12, 6.18, 7.0, 7.1
Timeline
- 2026-07-25: disclosed: Initial publication of the CVE record
- 2026-05-18: patched: Fix committed to the Linux kernel tree