HIGH Introduced in 6.19
drm/amdgpu UserQueue DoubleFree
CVE-2026-52987
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
KernelScan AI7.7HIGH
01Description
In the Linux kernel, the following vulnerability has been resolved: drm/amdgpu: avoid double drm_exec_fini() in userq validate When new_addition is true, amdgpu_userq_vm_validate() calls drm_exec_fini(&exec) before iterating over the collected HMM ranges and calling amdgpu_ttm_tt_get_user_pages(). If amdgpu_ttm_tt_get_user_pages() fails in that path, the code jumps to unlock_all and calls drm_exec_fini(&exec) a second time on the same exec object. drm_exec_fini() is not idempotent: it frees exec->objects and may also drop exec->contended and finalize the ww acquire context. Route that error path directly to the range cleanup once exec has already been finalized. Issue found using a prototype static analysis tool and confirmed by code review. (cherry picked from commit 2802952e4a07306da6ebe813ff1acacc5691851a)
02KernelScan AI Analysis
Risk summary
A local user with access to an AMD GPU device (via the DRM render node) can trigger a double-free of the drm_exec object during userptr validation failure by supplying invalid user pointers. This leads to heap memory corruption, potentially enabling privilege escalation, information disclosure, or kernel panic. The bug is reachable in the amdgpu userqueue path introduced in kernel 6.19.
Vulnerability analysis
The vulnerability is a double-free (CWE-415) in amdgpu_userq_vm_validate() in the amdgpu driver. When new_addition is true, the function calls drm_exec_fini(&exec) before iterating over collected HMM ranges and calling amdgpu_ttm_tt_get_user_pages(). If amdgpu_ttm_tt_get_user_pages() fails—e.g., due to an invalid or unmapped user pointer supplied by the caller—the original code jumps to the unlock_all label, which calls drm_exec_fini(&exec) a second time on the already-finalized exec object. Because drm_exec_fini() is not idempotent—it frees exec->objects, may drop exec->contended, and finalizes the ww acquire context—the second call operates on freed/invalid state, causing heap corruption. The fix routes the error path directly to a new free_ranges label, bypassing the second drm_exec_fini() call. Exploitation requires local access to an AMDGPU DRM device and the ability to submit a userqueue ioctl with a failing userptr, which is typically available to unprivileged users with access to the GPU render node.
Lifecycle
03Fix Versions
| Branch | Introduced | Fixed in | Patch commit |
|---|---|---|---|
| mainline | 6.19 | 7.1 | 508babf31036 |
| 7.0 | 6.19 | 7.0.10 | c7c3ae7c01e5 |