Database/Kernel, userspace & hypervisor
Linux kernel (drivers/gpu/drm/xe): Xe frees data that its exported dma-fences still point at - notably the timeline
Impact
Xe frees data that its exported dma-fences still point at - notably the timeline name - as soon as the owning submit queue is closed. Because those fences can already have been handed to a different process as a sync_file fd, the holder reads freed kernel memory. One tenant closing a queue corrupts state observed by whoever it shared the fence with, which is a genuine cross-process use-after-free.
Who can reach it
A container with /dev/dri/renderD* on an Intel Xe node exports a fence (sync_file / syncobj / dma-buf) to another process, then destroys its exec queue; the receiving side's subsequent access to the fence hits freed memory. Both sides are unprivileged, and fence sharing across process boundaries is a normal, supported operation.
What to do
Update to a kernel with the fix commits below, which adds RCU grace periods before freeing fence-referenced data. Interim: do not pass fence/sync fds across tenant boundaries, and restrict render-node access.
References
Related entries
- Linux kernel (drivers/gpu/drm/xe): A tenant that submits a deliberately malformed array bind to the Xe VM_BIND ioctlCVE-2025-38731 · Linux kernel (drivers/gpu/drm/xe)High
- Linux kernel (drivers/gpu/drm/xe): On the migration error path the previous fence is released before the code waits onCVE-2025-39740 · Linux kernel (drivers/gpu/drm/xe)High
- Linux kernel (drivers/gpu/drm/xe): The observation-config ioctl dereferences the config object after releasing the lockCVE-2025-71099 · Linux kernel (drivers/gpu/drm/xe)High
- Linux kernel (drivers/gpu/drm/xe): The Xe userptr path takes folio locks while holding the MMU notifier lock, whichCVE-2025-37868 · Linux kernel (drivers/gpu/drm/xe)Medium
- Linux kernel (drivers/gpu/drm/xe): A batched array of VM_BIND operations could evict other buffer objects belonging toCVE-2025-40086 · Linux kernel (drivers/gpu/drm/xe)Medium
- Linux kernel (drivers/gpu/drm/xe): A tenant's jobs can occupy the same copy engines the driver needs to service GPUCVE-2024-37026 · Linux kernel (drivers/gpu/drm/xe)Medium
This entry is curated: imported from vendor advisories with machine assistance, not yet individually verified. Confirm against your vendor's advisory before acting, and report anything wrong.