Database/Kernel, userspace & hypervisor
Linux kernel (drivers/gpu/drm/xe): The GPU VM is published into the id table before the create ioctl finishes with it
Impact
The GPU VM is published into the id table before the create ioctl finishes with it, so a tenant that guesses the id and calls VM destroy in parallel frees the VM while the create path is still using it. Use-after-free of a driver object under attacker timing control - the standard route from a tenant container to kernel code execution. The upstream fix names the attacker explicitly.
Who can reach it
Hostile tenant holding /dev/dri/renderD* on Intel xe: one thread spams VM_CREATE, another spams VM_DESTROY against the predictable next id. Unprivileged, no display access, no special platform features.
What to do
Update to a kernel carrying the fix (stable commits below; no fixed_in published). Interim: remove /dev/dri/renderD* from containers running untrusted code on xe nodes - the ioctl pair cannot be filtered selectively.
References
Related entries
- Linux kernel (drivers/gpu/drm/xe): The observation/OA path reuses one batch buffer and appends a batch-end command onCVE-2024-50090 · Linux kernel (drivers/gpu/drm/xe)High
- Linux kernel (drivers/gpu/drm/xe): Xe freed a job from inside timeout-detection-and-recovery while the submissionCVE-2024-50149 · Linux kernel (drivers/gpu/drm/xe)High
- Linux kernel (drivers/gpu/drm/xe): A tenant that suspends an exec queue and then closes it while the GuCCVE-2024-56552 · Linux kernel (drivers/gpu/drm/xe)High
- Linux kernel (drivers/gpu/drm/xe): Xe built its scatter-gather table from HMM page pointers without holding theCVE-2025-21939 · Linux kernel (drivers/gpu/drm/xe)High
- Linux kernel (drivers/gpu/drm/xe): A GPU TLB invalidation for a very large address range computes its length with aCVE-2025-37761 · Linux kernel (drivers/gpu/drm/xe)High
- Linux kernel (drivers/gpu/drm/xe): The error path of the Xe VRAM clear helper waits on a fence pointer that is onlyCVE-2025-37869 · Linux kernel (drivers/gpu/drm/xe)High
This entry is curated: imported from vendor advisories with machine assistance, not yet individually verified. Confirm against your vendor's advisory before acting, and report anything wrong.