KernelScan.io

HIGH Introduced in 6.18

drm/xe DmaBuf Import UAF

CVE-2026-52950

CVSS 7.8 / 10.0 NVD

CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

KernelScan AI7.4HIGH

01

In the Linux kernel, the following vulnerability has been resolved: drm/xe/dma-buf: fix UAF with retry loop Retry doesn't work here, since bo will be freed on error, leading to UAF. However, now that we do the alloc & init before the attach, we can now combine this as one unit and have the init do the alloc for us. This should make the retry safe. Reported by Sashiko. v2: Fix up the error unwind (CI) (cherry picked from commit 479669418253e0f27f8cf5db01a731352ea592e7)

02

Engine v0.3.0

Risk summary

A use-after-free vulnerability exists in the Intel Xe GPU driver's DMA-buf import path. When a retry loop is triggered during buffer object initialization, the buffer object (bo) is freed on error but the retry loop continues to reference it, leading to a use-after-free condition. A local unprivileged user with access to the GPU render node can exploit this to achieve privilege escalation, leak kernel memory, or cause a kernel crash.

Affecteddrivers/gpu/drm/xe/xe_dma_buf.c (DRM/Xe DMA-buf import)

Vulnerability analysis

The root cause is in xe_gem_prime_import() in the Xe DRM driver's DMA-buf import path. The code allocated a buffer object (bo) via xe_bo_alloc(), then passed it to xe_dma_buf_init_obj() which called xe_bo_init_locked(). The xe_bo_init_locked() function uses drm_exec retry semantics (drm_exec_retry_on_contention) — on contention, it frees the storage object and retries. However, the outer xe_gem_prime_import() function held a reference to the original 'bo' pointer and would attempt to use it after the retry freed it, creating a use-after-free. The fix restructures the code by removing the pre-allocation of 'bo' in the caller and renaming xe_dma_buf_init_obj() to xe_dma_buf_create_obj(), which now handles both allocation and initialization internally as a single atomic unit. This ensures that on retry, the allocation is also redone, eliminating the stale pointer. The attack surface requires local access to the GPU render node and the ability to trigger DMA-buf import operations, which is available to unprivileged users on standard configurations.

03

BranchIntroducedFixed inPatch commit
6.186.186.18.3339fdac6be02e
7.06.187.0.10827062952ed9
mainline6.187.1155a372a1cc5