PT-2026-51845 · Linux+2 · Linux Kernel+2
CVSS v3.1
7.8
High
| Vector | AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
Linux kernel (affected versions not specified)
Description
A flaw exists in the drm/xe/dma-buf subsystem involving race conditions when handling the
invalidate mappings hook during buffer object initialization and attachment. These races occur because a buffer object may be visible on the attachments list before it is fully initialized or after it has been freed following an initialization failure. An attacker could exploit these conditions to trigger a Use-After-Free (UAF) or a NULL pointer dereference in evict flags, potentially leading to system instability, crashes, and a Denial of Service (DoS).Recommendations
At the moment, there is no information about a newer version that contains a fix for this vulnerability.
Exploit
NULL Pointer Dereference
Use After Free
Race Condition
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Linuxmint
Linux Kernel
Ubuntu