* CVE-2026-72093: accel/amdxdna: Fix use-after-free in amdxdna_gem_dmabuf_mmap()
@ 2026-08-15 6:02 Greg Kroah-Hartman
0 siblings, 0 replies; only message in thread
From: Greg Kroah-Hartman @ 2026-08-15 6:02 UTC (permalink / raw)
To: linux-cve-announce; +Cc: Greg Kroah-Hartman
From: Greg Kroah-Hartman <gregkh@kernel.org>
Description
===========
In the Linux kernel, the following vulnerability has been resolved:
accel/amdxdna: Fix use-after-free in amdxdna_gem_dmabuf_mmap()
When vm_insert_pages() fails, the error path calls vma->vm_ops->close(vma)
which internally calls drm_gem_vm_close() → drm_gem_object_put(),
releasing the GEM object reference acquired at the start of the function.
However, the close_vma label then falls through to put_obj, which calls
drm_gem_object_put() a second time on the same object.
If the first put releases the last reference, the object is freed and the
second put accesses freed memory, causing a use-after-free.
Fix by returning directly from close_vma instead of falling through to
put_obj, since the close handler already performs all necessary cleanup
including the object put.
The Linux kernel CVE team has assigned CVE-2026-72093 to this issue.
Affected and fixed versions
===========================
Issue introduced in 6.16 with commit e486147c912f653ef4b60a6c7dbd4168a4c56a9f and fixed in 6.18.40 with commit 4e370b5289624f46a356dcc94f9f87025eaa6036
Issue introduced in 6.16 with commit e486147c912f653ef4b60a6c7dbd4168a4c56a9f and fixed in 7.1.5 with commit 5da885c39baa70f570a8be35a78e85a351f33918
Issue introduced in 6.16 with commit e486147c912f653ef4b60a6c7dbd4168a4c56a9f and fixed in 7.2-rc3 with commit 63bbf9ac5dde2ba85e7b39d0a0b7d540e6252ba4
Please see https://www.kernel.org for a full list of currently supported
kernel versions by the kernel community.
Unaffected versions might change over time as fixes are backported to
older supported kernel versions. The official CVE entry at
https://cve.org/CVERecord/?id=CVE-2026-72093
will be updated if fixes are backported, please check that for the most
up to date information about this issue.
Affected files
==============
The file(s) affected by this issue are:
drivers/accel/amdxdna/amdxdna_gem.c
Mitigation
==========
The Linux kernel CVE team recommends that you update to the latest
stable kernel version for this, and many other bugfixes. Individual
changes are never tested alone, but rather are part of a larger kernel
release. Cherry-picking individual commits is not recommended or
supported by the Linux kernel community at all. If however, updating to
the latest release is impossible, the individual changes to resolve this
issue can be found at these commits:
https://git.kernel.org/stable/c/4e370b5289624f46a356dcc94f9f87025eaa6036
https://git.kernel.org/stable/c/5da885c39baa70f570a8be35a78e85a351f33918
https://git.kernel.org/stable/c/63bbf9ac5dde2ba85e7b39d0a0b7d540e6252ba4
^ permalink raw reply [flat|nested] only message in thread
only message in thread, other threads:[~2026-08-15 6:12 UTC | newest]
Thread overview: (only message) (download: mbox.gz follow: Atom feed
-- links below jump to the message on this page --
2026-08-15 6:02 CVE-2026-72093: accel/amdxdna: Fix use-after-free in amdxdna_gem_dmabuf_mmap() Greg Kroah-Hartman
This is an external index of several public inboxes,
see mirroring instructions on how to clone and mirror
all data and code used by this external index.