In the Linux kernel, the following vulnerability has been resolved:
drm/gem: Try to fix change_handle ioctl, attempt 4
[airlied: just added some comments on how to reenable] On-list because the cat is out of the bag and we're clearly not good enough to figure this out in private. The story thus far:
5e28b7b94408 ("drm: Set old handle to NULL before prime swap in change_handle") tried to fix a race condition between the gem_close and gem_change_handle ioctls, but got a few things wrong:
- There's a confusion with the local variable handle, which is actually the new handle, and so the two-stage trick was actually applied to the wrong idr slot. 7164d78559b0 ("drm/gem: fix race between change_handle and handle_delete") tried to fix that by adding yet another code block, but forgot to add the error handling. Which meant we now have two paths, both kinda wrong.
- dc366607c41c ("drm: Replace old pointer to new idr") tried to apply another fix, but inconsistently, again because of the handle confusion - this would be the right fix (kinda, somewhat, it's a mess) if we'd do the two-stage approach for the new handle. Except that wasn't the intent of the original fix.
We also didn't have an igt merged for the original ioctl, which is a big no-go. This was attempted to address off-list in the original bugfix, and amd QA people claimed the bug was fixed now. Very clearly that's not the case. Here's my attempt to sort this out:
- Rename the local variable to new_handle, the old aliasing with args->handle is just too dangerously confusing.
- Merge the gem obj lookup with the two-stage idr_replace so that we avoid getting ourselves confused there.
- This means we don't have a surplus temporary reference anymore, only an inherited from the idr. A concurrent gem_close on the new_handle could steal that. Fix that with the same two-stage approach create_tail uses. This is a bit overkill as documented in the comment, but I also don't trust my ability to understand this all correctly, so go with the established pattern we have from other ioctls instead for maximum paranoia.
- Adjust error paths. I've tried to make the error and success paths common, because they are identical except for which handle is removed and on which we call idr_replace to (re)install the object again. But that made things messier to read, so I've left it at the more verbose version, which unfortunately hides the symmetry in the entire code flow a bit.
- While at it, also replace the 7 space indent with 1 tab.
And finally, because I flat out don't trust my abilities here at all anymore:
- Disable the ioctl until we have the igt situation and everything else sorted out on-list and with full consensus.
v2:
Sashiko noticed that I didn't handle the error path for idr_replace correctly, it must be checked with IS_ERR_OR_NULL like in gem_handle_delete. So yeah, definitely should just the existing paths 1:1 because this is endless amounts of tricky.
Also add the Fixes: line for the original ioctl, I forgot that too.
CVSS Details
- CVSS 3.1 Base Score: 7.8
- CVSS 3.1 Vector: (CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H)
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Amazon_linux_2023 | — | Upgrade kernel6.18-modules-extraUpgrade perf6.18Upgrade kernel6.18-debuginfo-common-aarch64Upgrade perf6.18-debuginfoUpgrade bpftool6.18Upgrade kernel6.18-modules-extra-commonUpgrade kernel6.18Upgrade microvm-kernel6.18Upgrade bpftool6.18-debuginfoUpgrade kernel6.18-headersUpgrade kernel6.18-develUpgrade kernel6.18-debuginfoUpgrade python3-perf6.18Upgrade kernel6.18-tools-debuginfoUpgrade python3-perf6.18-debuginfoUpgrade kernel6.18-tools-develUpgrade kernel6.18-toolsUpgrade kernel-livepatch-6.18.36-69.134Upgrade kernel6.18-debuginfo-common-x86_64 | Jul 21, 2026 | Jun 25, 2026 |
| Redhat_linux | — | No solution exists | Jul 17, 2026 | Jun 25, 2026 |
| Ubuntu | — | Upgrade linux-image-7.0.0-1019-raspi-realtimeUpgrade linux-image-virtualUpgrade linux-image-aws-64kUpgrade linux-image-realtimeUpgrade linux-image-gke-7.0Upgrade linux-image-raspi-7.0Upgrade linux-image-raspi-realtimeUpgrade linux-image-realtime-64kUpgrade linux-image-oracleUpgrade linux-image-generic-hwe-24.04Upgrade linux-image-generic-hwe-26.04Upgrade linux-image-7.0.0-1011-oracle-64kUpgrade linux-image-7.0.0-1019-raspiUpgrade linux-image-generic-64k-7.0Upgrade linux-image-7.0.0-31-generic-64kUpgrade linux-image-gkeUpgrade linux-image-gke-hwe-26.04Upgrade linux-image-raspi-realtime-7.0Upgrade linux-image-aws-64k-7.0Upgrade linux-image-realtime-7.0Upgrade linux-image-virtual-7.0Upgrade linux-image-7.0.0-1013-oemUpgrade linux-image-gcp-7.0Upgrade linux-image-7.0.0-1014-azureUpgrade linux-image-oracle-64kUpgrade linux-image-gke-64k-hwe-26.04Upgrade linux-image-generic-7.0Upgrade linux-image-7.0.0-1018-nvidia-64kUpgrade linux-image-7.0.0-1006-gke-64kUpgrade linux-image-azure-7.0Upgrade linux-image-gcp-64k-7.0Upgrade linux-image-generic-64k-hwe-24.04Upgrade linux-image-realtime-64k-7.0Upgrade linux-image-oracle-64k-7.0Upgrade linux-image-ibmUpgrade linux-image-7.0.0-31-realtimeUpgrade linux-image-nvidiaUpgrade linux-image-azure-lts-26.04Upgrade linux-image-nvidia-bos-7.0Upgrade linux-image-nvidia-bosUpgrade linux-image-nvidia-7.0Upgrade linux-image-nvidia-64k-hwe-26.04Upgrade linux-image-7.0.0-2018-nvidia-bos-64kUpgrade linux-image-nvidia-bos-64kUpgrade linux-image-generic-64kUpgrade linux-image-nvidia-64kUpgrade linux-image-nvidia-64k-7.0Upgrade linux-image-7.0.0-1006-gkeUpgrade linux-image-oem-26.04aUpgrade linux-image-ibm-7.0Upgrade linux-image-7.0.0-1013-ibmUpgrade linux-image-7.0.0-1012-aws-64kUpgrade linux-image-realtime-hwe-26.04Upgrade linux-image-realtime-64k-hwe-26.04Upgrade linux-image-raspiUpgrade linux-image-azureUpgrade linux-image-7.0.0-2018-nvidia-bosUpgrade linux-image-nvidia-bos-64k-7.0Upgrade linux-image-oem-7.0Upgrade linux-image-oem-26.04Upgrade linux-image-nvidia-hwe-26.04Upgrade linux-image-7.0.0-1018-nvidiaUpgrade linux-image-7.0.0-1012-awsUpgrade linux-image-genericUpgrade linux-image-gcp-64kUpgrade linux-image-7.0.0-31-realtime-64kUpgrade linux-image-gke-64k-7.0Upgrade linux-image-gke-64kUpgrade linux-image-7.0.0-1011-gcpUpgrade linux-image-virtual-hwe-26.04Upgrade linux-image-7.0.0-31-genericUpgrade linux-image-oracle-7.0Upgrade linux-image-7.0.0-1011-oracleUpgrade linux-image-oem-26.04bUpgrade linux-image-7.0.0-1011-gcp-64kUpgrade linux-image-virtual-hwe-24.04Upgrade linux-image-gcpUpgrade linux-image-generic-64k-hwe-26.04Upgrade linux-image-awsUpgrade linux-image-aws-7.0 | Sep 14, 2026 | Sep 7, 2026 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub