Database/Kernel, userspace & hypervisor
Linux kernel (drivers/gpu/drm/xe): Xe freed a job from inside timeout-detection-and-recovery while the submission
Impact
Xe freed a job from inside timeout-detection-and-recovery while the submission thread could still be running it, giving a use-after-free on the job object. The trigger is a GPU hang, and any tenant can cause a GPU hang on demand with a runaway shader - so this converts a self-inflicted hang into kernel memory corruption on a node shared with other tenants.
Who can reach it
An unprivileged container with /dev/dri/renderD* on an Intel Xe node submits a job that never completes; the TDR path then fires and races the run_job thread. Deliberately hanging the GPU is trivial from userspace, which makes this attacker-scheduled rather than incidental.
What to do
Update to a kernel with the fix commits below, which defers the free to the scheduler. Interim: restrict render-node access to trusted workloads and monitor for repeated GPU resets, which are the signal that someone is exercising this path.
References
Related entries
- Linux kernel (drivers/gpu/drm/xe): A tenant that suspends an exec queue and then closes it while the GuCCVE-2024-56552 · Linux kernel (drivers/gpu/drm/xe)High
- Linux kernel (drivers/gpu/drm/xe): Xe built its scatter-gather table from HMM page pointers without holding theCVE-2025-21939 · Linux kernel (drivers/gpu/drm/xe)High
- Linux kernel (drivers/gpu/drm/xe): A GPU TLB invalidation for a very large address range computes its length with aCVE-2025-37761 · Linux kernel (drivers/gpu/drm/xe)High
- Linux kernel (drivers/gpu/drm/xe): The error path of the Xe VRAM clear helper waits on a fence pointer that is onlyCVE-2025-37869 · Linux kernel (drivers/gpu/drm/xe)High
- Linux kernel (drivers/gpu/drm/xe): Xe frees data that its exported dma-fences still point at - notably the timelineCVE-2025-38703 · Linux kernel (drivers/gpu/drm/xe)High
- Linux kernel (drivers/gpu/drm/xe): A tenant that submits a deliberately malformed array bind to the Xe VM_BIND ioctlCVE-2025-38731 · Linux kernel (drivers/gpu/drm/xe)High
This entry is curated: imported from vendor advisories with machine assistance, not yet individually verified. Confirm against your vendor's advisory before acting, and report anything wrong.