CVE-2026-64517: drm/xe/gsc: Fix double-free of managed BO in error path
Greg Kroah-Hartman <[email protected]> Sat, 25 Jul 2026 11:13:38 +0200
| Newsgroups | org.kernel.vger.linux-cve-announce |
|---|---|
| Message-ID | <2026072537-CVE-2026-64517-444d@gregkh> |
From: Greg Kroah-Hartman <[email protected]> Description =========== In the Linux kernel, the following vulnerability has been resolved: drm/xe/gsc: Fix double-free of managed BO in error path The error path in xe_gsc_init_post_hwconfig() explicitly frees a BO allocated with xe_managed_bo_create_pin_map() via xe_bo_unpin_map_no_vm(). Since the managed BO already has a devm cleanup action registered, this causes a double-free when devm unwinds during probe failure. Remove the explicit free and let devm handle it, consistent with all other xe_managed_bo_create_pin_map() callers. (cherry picked from commit 71d61e3e299a17139e47f980a4d6f425b2c59bf7) The Linux kernel CVE team has assigned CVE-2026-64517 to this issue. Affected and fixed versions =========================== Issue introduced in 6.12 with commit 2e5d47fe7839298fa096970e184aac9bf82c3bd3 and fixed in 6.12.92 with commit 7cb975fcd4777e7bad688f66aa0c10c16dd8276b Issue introduced in 6.12 with commit 2e5d47fe7839298fa096970e184aac9bf82c3bd3 and fixed in 6.18.34 with commit 2c890e71ae26fa32f5a96c3694b71a2c310940e7 Issue introduced in 6.12 with commit 2e5d47fe7839298fa096970e184aac9bf82c3bd3 and fixed in 7.0.11 with commit 889f70de2b51a877339e1979aab95111b41bed75 Issue introduced in 6.12 with commit 2e5d47fe7839298fa096970e184aac9bf82c3bd3 and fixed in 7.1 with commit d3ded53fab90996e7d94a39049e11962dd066725 Please see https://www.kernel.org for a full list of currently supported kernel versions by the kernel community. Unaffected versions might change over time as fixes are backported to older supported kernel versions. The official CVE entry at https://cve.org/CVERecord/?id=CVE-2026-64517 will be updated if fixes are backported, please check that for the most up to date information about this issue. Affected files ============== The file(s) affected by this issue are: drivers/gpu/drm/xe/xe_gsc.c Mitigation ========== The Linux kernel CVE team recommends that you update to the latest stable kernel version for this, and many other bugfixes. Individual changes are never tested alone, but rather are part of a larger kernel release. Cherry-picking individual commits is not recommended or supported by the Linux kernel community at all. If however, updating to the latest release is impossible, the individual changes to resolve this issue can be found at these commits: https://git.kernel.org/stable/c/7cb975fcd4777e7bad688f66aa0c10c16dd8276b https://git.kernel.org/stable/c/2c890e71ae26fa32f5a96c3694b71a2c310940e7 https://git.kernel.org/stable/c/889f70de2b51a877339e1979aab95111b41bed75 https://git.kernel.org/stable/c/d3ded53fab90996e7d94a39049e11962dd066725