CVE-2026-52976

Severity CVSS v4.0:
Pending analysis
Type:
CWE-416 Use After Free
Publication date:
24/06/2026
Last modified:
27/07/2026

Description

In the Linux kernel, the following vulnerability has been resolved:<br /> <br /> drm/xe: Fix error cleanup in xe_exec_queue_create_ioctl()<br /> <br /> Two error handling issues exist in xe_exec_queue_create_ioctl():<br /> <br /> 1. When xe_hw_engine_group_add_exec_queue() fails, the error path jumps<br /> to put_exec_queue which skips xe_exec_queue_kill(). If the VM is in<br /> preempt fence mode, xe_vm_add_compute_exec_queue() has already added<br /> the queue to the VM&amp;#39;s compute exec queue list. Skipping the kill<br /> leaves the queue on that list, leading to a dangling pointer after<br /> the queue is freed.<br /> <br /> 2. When xa_alloc() fails after xe_hw_engine_group_add_exec_queue() has<br /> succeeded, the error path does not call<br /> xe_hw_engine_group_del_exec_queue() to remove the queue from the hw<br /> engine group list. The queue is then freed while still linked into<br /> the hw engine group, causing a use-after-free.<br /> <br /> Fix both by:<br /> - Changing the xe_hw_engine_group_add_exec_queue() failure path to jump<br /> to kill_exec_queue so that xe_exec_queue_kill() properly removes the<br /> queue from the VM&amp;#39;s compute list.<br /> - Adding a del_hw_engine_group label before kill_exec_queue for the<br /> xa_alloc() failure path, which removes the queue from the hw engine<br /> group before proceeding with the rest of the cleanup.<br /> <br /> (cherry picked from commit 37c831f401746a45d510b312b0ed7a77b1e06ec8)

Vulnerable products and versions

CPE From Up to
cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:* 6.12 (including) 6.12.91 (excluding)
cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:* 6.13 (including) 6.18.33 (excluding)
cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:* 6.19 (including) 7.0.10 (excluding)
cpe:2.3:o:linux:linux_kernel:7.1:rc1:*:*:*:*:*:*