Database/Kernel, userspace & hypervisor
Linux kernel (drivers/gpu/drm): DRM core stores a pointer to the caller's struct pid before taking a reference on it
Impact
DRM core stores a pointer to the caller's struct pid before taking a reference on it, so two processes issuing ioctls on the same DRM fd can drive that pid to refcount zero while it is still referenced. This is a use-after-free of a core kernel object reachable from any GPU node, on any driver - a strong local privilege-escalation primitive out of a tenant container.
Who can reach it
Any tenant holding any /dev/dri node (renderD* is enough - the path is in drm_file, not a driver). Share the fd across two processes via fork() or SCM_RIGHTS and have both issue DRM ioctls in a loop. Requires CONFIG_PREEMPT_RCU, which is common on distro kernels. Driver-independent: amdgpu, xe, i915, nouveau, virtio-gpu are all exposed.
What to do
Update to 6.6.37 or later (or the equivalent fix in your stable series). No workable interim control other than removing /dev/dri from tenant containers - this is core DRM, hit by every ioctl.
References
Related entries
- Linux kernel (drivers/gpu/drm): Three lines of userspace - mmap a GEM object with PROT_WRITE and MAP_PRIVATE, thenCVE-2024-39497 · Linux kernel (drivers/gpu/drm)Medium
- Linux kernel (drivers/gpu/drm): The dma_buf pointer cached on a GEM object goes stale the moment userspace drops theCVE-2025-38674 · Linux kernel (drivers/gpu/drm)Medium
- Linux kernel (drivers/gpu/drm): The shared GPU SVM layer mis-computes the mapping order when an HMM range onlyCVE-2025-40336 · Linux kernel (drivers/gpu/drm)High
- Linux kernel (drivers/gpu/drm): The shared shmem GEM mmap helper dropped a reference it never owned, so the bufferCVE-2022-48981 · Linux kernel (drivers/gpu/drm)High
- Linux kernel (drivers/gpu/drm): The shared VRAM buddy allocator reports success for a ranged allocation it neverCVE-2024-26911 · Linux kernel (drivers/gpu/drm)High
- Linux kernel mlx5_ib (shared receive queue): The max_sge attribute for a shared receive queue is taken from the userCVE-2024-40990 · Linux kernel mlx5_ib (shared receive queue)High
This entry is curated: imported from vendor advisories with machine assistance, not yet individually verified. Confirm against your vendor's advisory before acting, and report anything wrong.