PT-2026-51881 · Linux+2 · Linux Kernel+2

·

CVE-2026-52987

·

Published

2026-04-24

·

Updated

2026-09-07

CVSS v3.1

7.8

High

VectorAV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Linux kernel (affected versions not specified)
Description A double free flaw exists in the drm/amdgpu component within the userq validate function. The issue occurs when amdgpu userq vm validate() calls the drm exec fini() function on an execution object, and subsequently calls it a second time if amdgpu ttm tt get user pages() fails. Because drm exec fini() is not idempotent, it may incorrectly free objects and finalize the ww acquire context, potentially leading to a denial of service or unpredictable system behavior.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Exploit

Multiple Releases of Same Resource or Handle

Double Free

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

BDU:2026-13937
CVE-2026-52987
USN-8566-1
USN-8568-1
USN-8569-1
USN-8593-1
USN-8603-1
USN-8618-1
USN-8663-1
USN-8664-1
USN-8728-1

Affected Products

Linuxmint
Linux Kernel
Ubuntu