CVE-2026-52950
drm/xe/dma-buf: fix UAF with retry loop
CVSS Score
7.8
EPSS Score
0.0%
EPSS Percentile
0th
In the Linux kernel, the following vulnerability has been resolved: drm/xe/dma-buf: fix UAF with retry loop Retry doesn't work here, since bo will be freed on error, leading to UAF. However, now that we do the alloc & init before the attach, we can now combine this as one unit and have the init do the alloc for us. This should make the retry safe. Reported by Sashiko. v2: Fix up the error unwind (CI) (cherry picked from commit 479669418253e0f27f8cf5db01a731352ea592e7)
| Vendor | linux |
| Product | linux |
| Ecosystems | |
| Industries | Technology |
| Published | Jun 24, 2026 |
| Last Updated | Aug 5, 2026 |
Stay Ahead of the Next One
Get instant alerts for linux linux
Be the first to know when new high vulnerabilities affecting linux linux are published โ delivered to Slack, Telegram or Discord.
Get Free Alerts โ
Free ยท No credit card ยท 60 sec setup
CVSS v3 Breakdown
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H Attack Vector
Attack Complexity
Privileges Required
User Interaction
Scope
Confidentiality
Integrity
Availability
Affected Versions
Linux / Linux
eb289a5f6cc668853f9b2ea6aca04afe58ed11c7 < 39fdac6be02eb7c3460518c1c4085f75f935c4ce eb289a5f6cc668853f9b2ea6aca04afe58ed11c7 < 827062952ed9bdf4220466c1f05ce452d04bdedf eb289a5f6cc668853f9b2ea6aca04afe58ed11c7 < 155a372a1cc50fa93387c5d3cdfd614a61e1afd1
Linux / Linux
6.18
References
git.kernel.org: https://git.kernel.org/stable/c/39fdac6be02eb7c3460518c1c4085f75f935c4ce git.kernel.org: https://git.kernel.org/stable/c/827062952ed9bdf4220466c1f05ce452d04bdedf git.kernel.org: https://git.kernel.org/stable/c/155a372a1cc50fa93387c5d3cdfd614a61e1afd1 access.redhat.com: https://access.redhat.com/security/cve/CVE-2026-52950 bugzilla.redhat.com: https://bugzilla.redhat.com/show_bug.cgi?id=2492318 security.access.redhat.com: https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-52950.json access.redhat.com: https://access.redhat.com/errata/RHSA-2026:42919 access.redhat.com: https://access.redhat.com/errata/RHSA-2026:45192