PT-2026-106509 · Linux · Linux

CVE-2026-98180

·

Published

2026-10-06

·

Updated

2026-10-06

CVSS v3.1

7.1

High

VectorAV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:H
In the Linux kernel, the following vulnerability has been resolved:
drm/msm: RCU-free the scheduler-containing ring and VM objects
Both struct msm ringbuffer and struct msm gem vm embed a struct drm gpu scheduler. msm ringbuffer destroy() and the VM free callback msm gem vm free() call drm sched fini() on the embedded scheduler and then free the containing object with plain kfree().
drm sched fence get timeline name() returns fence->sched->name, and the scheduler fence keeps a .release callback so it is not ops-detached on signalling. A finished fence exported to userspace (the submit out-fence, or a VM BIND fence, via sync file / drm syncobj) keeps pointing at the embedded scheduler after the ring/VM is freed, so a later get timeline name() -- reachable unprivileged through SYNC IOC FILE INFO -- dereferences freed slab memory (KASAN slab-use-after-free read).
Per the dma-fence lifetime contract the exporter must keep the data backing a signalled fence alive for an RCU grace period. Free the scheduler-containing objects with kfree rcu() instead of kfree().

Fix

Found an issue in the description? Have something to add? Feel free to write us 👾

Related Identifiers

CVE-2026-98180

Affected Products

Linux