PT-2026-61338 · Linux+1 · Linux Kernel+1

CVE-2026-64021

·

Published

2026-05-21

·

Updated

2026-09-07

CVSS v2.0

4.6

Medium

VectorAV:L/AC:L/Au:S/C:N/I:N/A:C
Name of the Vulnerable Software and Affected Versions Linux kernel (affected versions not specified)
Description A memory leak occurs in the xe oa stream open ioctl() function when the param.exec q->width variable is greater than 1. In this scenario, the function returns an error without executing the cleanup path, causing a reference to the exec queue obtained via xe exec queue lookup() to be leaked. Because the exec queue maintains a reference to the xe file, both the queue and the file's private state remain pinned in memory indefinitely, as the leak occurs outside the file's exec queue xarray and cannot be released during file closure.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Exploit

Memory Leak

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

BDU:2026-14284
CVE-2026-64021
OPENSUSE-SU-2026:21555-1
SUSE-SU-2026:23066-1
SUSE-SU-2026:23068-1
SUSE-SU-2026:23221-1
SUSE-SU-2026:23231-1
SUSE-SU-2026:23237-1
USN-8593-1
USN-8603-1
USN-8618-1
USN-8663-1
USN-8664-1
USN-8728-1

Affected Products

Linux Kernel
Ubuntu