In the Linux kernel, the following vulnerability has been resolved:
drm/xe: Don't free job in TDR
Freeing job in TDR is not safe as TDR can pass the run_job thread resulting in UAF. It is only safe for free job to naturally be called by the scheduler. Rather free job in TDR, add to pending list.
(cherry picked from commit ea2f6a77d0c40d97f4a4dc93fee4afe15d94926d)
CVSS Details
- CVSS 3.1 Base Score: 7.8
- CVSS 3.1 Vector: (CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H)
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Debian | — | Upgrade linux | Jul 27, 2026 | Jul 27, 2026 |
| Ubuntu | — | Upgrade linux-image-generic-64k-hwe-24.04Upgrade linux-image-6.11.0-1008-raspiUpgrade linux-image-oracleUpgrade linux-image-6.11.0-1009-gcpUpgrade linux-image-azure-fdeUpgrade linux-image-lowlatencyUpgrade linux-image-virtualUpgrade linux-image-6.11.0-1005-realtimeUpgrade linux-image-lowlatency-64kUpgrade linux-image-oem-24.04bUpgrade linux-image-6.11.0-1011-oracle-64kUpgrade linux-image-genericUpgrade linux-image-6.11.0-1010-lowlatency-64kUpgrade linux-image-awsUpgrade linux-image-virtual-hwe-24.04Upgrade linux-image-6.11.0-1009-azure-fdeUpgrade linux-image-generic-64kUpgrade linux-image-oem-24.04Upgrade linux-image-raspiUpgrade linux-image-oracle-64kUpgrade linux-image-6.11.0-18-generic-64kUpgrade linux-image-generic-hwe-24.04Upgrade linux-image-6.11.0-1009-azureUpgrade linux-image-gcpUpgrade linux-image-6.11.0-1011-oracleUpgrade linux-image-azureUpgrade linux-image-6.11.0-1010-lowlatencyUpgrade linux-image-realtimeUpgrade linux-image-6.11.0-18-genericUpgrade linux-image-6.11.0-1009-awsUpgrade linux-image-realtime-hwe-24.04Upgrade linux-image-6.11.0-1015-oemUpgrade linux-image-oem-24.04a | Feb 20, 2025 | Nov 7, 2024 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub