PT-2026-106509 · Linux · Linux

CVE-2026-98180

·

Publicado

2026-10-06

·

Atualizado

2026-10-06

CVSS v3.1

7.1

Alta

VetorAV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:H
In the Linux kernel, the following vulnerability has been resolved:
drm/msm: RCU-free the scheduler-containing ring and VM objects
Both struct msm ringbuffer and struct msm gem vm embed a struct drm gpu scheduler. msm ringbuffer destroy() and the VM free callback msm gem vm free() call drm sched fini() on the embedded scheduler and then free the containing object with plain kfree().
drm sched fence get timeline name() returns fence->sched->name, and the scheduler fence keeps a .release callback so it is not ops-detached on signalling. A finished fence exported to userspace (the submit out-fence, or a VM BIND fence, via sync file / drm syncobj) keeps pointing at the embedded scheduler after the ring/VM is freed, so a later get timeline name() -- reachable unprivileged through SYNC IOC FILE INFO -- dereferences freed slab memory (KASAN slab-use-after-free read).
Per the dma-fence lifetime contract the exporter must keep the data backing a signalled fence alive for an RCU grace period. Free the scheduler-containing objects with kfree rcu() instead of kfree().

Correção

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Identificadores relacionados

CVE-2026-98180

Produtos afetados

Linux