Database/Kernel, userspace & hypervisor
Linux kernel dma-fence: lost RCU protection after signalling allows use-after-free of fence name strings
Impact
An earlier fix changed the dma-fence timeline/driver name accessors to test the ops pointer instead of the signalled bit. Because ops is cleared only for implementations that provide neither a release nor a wait callback - which is not the case for most drivers - those implementations lost their RCU protection once a fence was signalled, so the returned string can be read after the backing object is freed. dma-fence is the synchronisation primitive every GPU and accelerator driver builds on, and these names are read by debugfs, tracepoints and sync-file introspection, so the read can be triggered from ordinary observability paths on a busy GPU node. A use-after-free read of kernel memory is an information leak and a potential crash; the record does not claim a demonstrated privilege escalation and carries no CVSS score.
Who can reach it
Local: a process that can observe fences while they signal - debugfs or tracepoint access, or a tenant exercising a driver's sync-file and fence-info interfaces through a GPU device node. No remote reach; no authentication beyond local access to those interfaces.
What to do
Take the stable kernel update (v3 of the patch) that checks both the signalling state and the ops pointer, then drain and reboot each node. Restricting debugfs and tracefs to administrators reduces the easiest trigger in the meantime. The record names only the two stable commits, not a fixed release version.
References
Related entries
- Linux kernel arm64: LSE percpu ops on 8/16-bit types read and write 32 bits of memoryCVE-2026-98248 · Linux kernel arm64 percpu operations (LSE atomics on 8- and 16-bit types)Unscored
- Linux kernel RDMA/core: iWARP port mapper initialises its refcount after publishing the requestCVE-2026-98252 · Linux kernel RDMA/core iWARP port mapper (iwpm_get_nlmsg_request refcount init)Unscored
- Linux kernel perf: NULL pmu dereference when a PMU module unloads with an event openCVE-2026-98268 · Linux kernel perf (is_include_guest_event / mediated PMU accounting)Unscored
- Linux kernel x86/kprobes: wrong return address when probing a CS-prefixed CALL crashes the hostCVE-2026-98273 · Linux kernel x86/kprobes (int3_emulate_call instruction length)Unscored
- powerpc/iommu: TCE IOBA range check ignores npages, allowing out-of-range table accessCVE-2026-98282 · Linux kernel powerpc/iommu (iommu_tce_check_ioba npages validation)Unscored
- KVM PPC Book3S HV: use-after-free on nested guest struct during all-LPID tlbie emulationCVE-2026-98283 · Linux kernel KVM PPC Book3S HV (kvmhv_emulate_tlbie_all_lpid)Unscored
This entry is curated: imported from vendor advisories with machine assistance, not yet individually verified. Confirm against your vendor's advisory before acting, and report anything wrong.