PT-2026-106509 · Linux · Linux
CVE-2026-98180
·
Publicado
2026-10-06
·
Atualizado
2026-10-06
CVSS v3.1
7.1
Alta
| Vetor | AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:H |
In the Linux kernel, the following vulnerability has been resolved:
drm/msm: RCU-free the scheduler-containing ring and VM objects
Both struct msm ringbuffer and struct msm gem vm embed a struct
drm gpu scheduler. msm ringbuffer destroy() and the VM free callback
msm gem vm free() call drm sched fini() on the embedded scheduler and then
free the containing object with plain kfree().
drm sched fence get timeline name() returns fence->sched->name, and the
scheduler fence keeps a .release callback so it is not ops-detached on
signalling. A finished fence exported to userspace (the submit out-fence, or
a VM BIND fence, via sync file / drm syncobj) keeps pointing at the embedded
scheduler after the ring/VM is freed, so a later get timeline name() --
reachable unprivileged through SYNC IOC FILE INFO -- dereferences freed slab
memory (KASAN slab-use-after-free read).
Per the dma-fence lifetime contract the exporter must keep the data backing a
signalled fence alive for an RCU grace period. Free the scheduler-containing
objects with kfree rcu() instead of kfree().
Correção
Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾
Identificadores relacionados
Produtos afetados
Linux