CVE-2026-52987CWE-1341

CVE-2026-52987

High · published June 24, 2026

CVSS v3.1
7.8
EPSS
0%
Percentile
3.4
In the wild
Unconfirmed
What it is

In the Linux kernel, the following vulnerability has been resolved:

drm/amdgpu: avoid double drm_exec_fini() in userq validate

When new_addition is true, amdgpu_userq_vm_validate() calls

drm_exec_fini(&exec) before iterating over the collected HMM ranges and

calling amdgpu_ttm_tt_get_user_pages().

If amdgpu_ttm_tt_get_user_pages() fails in that path, the code jumps to

unlock_all and calls drm_exec_fini(&exec) a second time on the same

exec object. drm_exec_fini() is not idempotent: it frees exec->objects

and may also drop exec->contended and finalize the ww acquire context.

Route that error path directly to the range cleanup once exec has

already been finalized.

Issue found using a prototype static analysis tool

and confirmed by code review.

(cherry picked from commit 2802952e4a07306da6ebe813ff1acacc5691851a)

The record
Technical detail
CVSS v3.1
7.8 · HIGH
Vector
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
CVSS v4.0
Not supplied
EPSS
0.00137 · 3.4th percentile
Weakness
CWE-1341 · Multiple Releases of Same Resource or Handle
Published
2026-06-24T21:17Z
Affected products (2)
ProductVersionsFixed in
linux/linux_kernel≥ 6.19, < 7.0.107.0.10
linux/linux_kernelall versions
References (5)
EPSS history
Timeline
  • 24 JUN 16:29Z
    drm/amdgpu: avoid double drm_exec_fini() in userq validate
    cvelistv5