HIGH Introduced in 6.18
drm/xe DmaBuf Import UAF
CVE-2026-52950
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
KernelScan AI7.4HIGH
01Description
In the Linux kernel, the following vulnerability has been resolved: drm/xe/dma-buf: fix UAF with retry loop Retry doesn't work here, since bo will be freed on error, leading to UAF. However, now that we do the alloc & init before the attach, we can now combine this as one unit and have the init do the alloc for us. This should make the retry safe. Reported by Sashiko. v2: Fix up the error unwind (CI) (cherry picked from commit 479669418253e0f27f8cf5db01a731352ea592e7)
02KernelScan AI Analysis
Risk summary
A use-after-free vulnerability exists in the Intel Xe GPU driver's DMA-buf import path. When a retry loop is triggered during buffer object initialization, the buffer object (bo) is freed on error but the retry loop continues to reference it, leading to a use-after-free condition. A local unprivileged user with access to the GPU render node can exploit this to achieve privilege escalation, leak kernel memory, or cause a kernel crash.
Vulnerability analysis
The root cause is in xe_gem_prime_import() in the Xe DRM driver's DMA-buf import path. The code allocated a buffer object (bo) via xe_bo_alloc(), then passed it to xe_dma_buf_init_obj() which called xe_bo_init_locked(). The xe_bo_init_locked() function uses drm_exec retry semantics (drm_exec_retry_on_contention) — on contention, it frees the storage object and retries. However, the outer xe_gem_prime_import() function held a reference to the original 'bo' pointer and would attempt to use it after the retry freed it, creating a use-after-free. The fix restructures the code by removing the pre-allocation of 'bo' in the caller and renaming xe_dma_buf_init_obj() to xe_dma_buf_create_obj(), which now handles both allocation and initialization internally as a single atomic unit. This ensures that on retry, the allocation is also redone, eliminating the stale pointer. The attack surface requires local access to the GPU render node and the ability to trigger DMA-buf import operations, which is available to unprivileged users on standard configurations.
Lifecycle
03Fix Versions
| Branch | Introduced | Fixed in | Patch commit |
|---|---|---|---|
| 6.18 | 6.18 | 6.18.33 | 39fdac6be02e |
| 7.0 | 6.18 | 7.0.10 | 827062952ed9 |
| mainline | 6.18 | 7.1 | 155a372a1cc5 |