CVE-2026-52976
Severity CVSS v4.0:
Pending analysis
Type:
CWE-416
Use After Free
Publication date:
24/06/2026
Last modified:
27/07/2026
Description
In the Linux kernel, the following vulnerability has been resolved:<br />
<br />
drm/xe: Fix error cleanup in xe_exec_queue_create_ioctl()<br />
<br />
Two error handling issues exist in xe_exec_queue_create_ioctl():<br />
<br />
1. When xe_hw_engine_group_add_exec_queue() fails, the error path jumps<br />
to put_exec_queue which skips xe_exec_queue_kill(). If the VM is in<br />
preempt fence mode, xe_vm_add_compute_exec_queue() has already added<br />
the queue to the VM&#39;s compute exec queue list. Skipping the kill<br />
leaves the queue on that list, leading to a dangling pointer after<br />
the queue is freed.<br />
<br />
2. When xa_alloc() fails after xe_hw_engine_group_add_exec_queue() has<br />
succeeded, the error path does not call<br />
xe_hw_engine_group_del_exec_queue() to remove the queue from the hw<br />
engine group list. The queue is then freed while still linked into<br />
the hw engine group, causing a use-after-free.<br />
<br />
Fix both by:<br />
- Changing the xe_hw_engine_group_add_exec_queue() failure path to jump<br />
to kill_exec_queue so that xe_exec_queue_kill() properly removes the<br />
queue from the VM&#39;s compute list.<br />
- Adding a del_hw_engine_group label before kill_exec_queue for the<br />
xa_alloc() failure path, which removes the queue from the hw engine<br />
group before proceeding with the rest of the cleanup.<br />
<br />
(cherry picked from commit 37c831f401746a45d510b312b0ed7a77b1e06ec8)
Impact
Base Score 3.x
7.80
Severity 3.x
HIGH
Vulnerable products and versions
| CPE | From | Up to |
|---|---|---|
| cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:* | 6.12 (including) | 6.12.91 (excluding) |
| cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:* | 6.13 (including) | 6.18.33 (excluding) |
| cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:* | 6.19 (including) | 7.0.10 (excluding) |
| cpe:2.3:o:linux:linux_kernel:7.1:rc1:*:*:*:*:*:* |
To consult the complete list of CPE names with products and versions, see this page
References to Advisories, Solutions, and Tools
- https://git.kernel.org/stable/c/1be55646d8a2035343b012dcb12210db7bb8b056
- https://git.kernel.org/stable/c/753b149d5a433eb19e0c1b0eb4526a6e26120d1f
- https://git.kernel.org/stable/c/f3cc22d4df3ed58439ea7e21daa54c3608e03b78
- https://git.kernel.org/stable/c/f93b00161213a0fe9f7ff1d8498ee5ca9e0a5c43
- https://access.redhat.com/errata/RHSA-2026:42919
- https://access.redhat.com/errata/RHSA-2026:45192
- https://access.redhat.com/security/cve/CVE-2026-52976
- https://bugzilla.redhat.com/show_bug.cgi?id=2492284
- https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-52976.json



