In the Linux kernel, the following vulnerability has been resolved:
drm/panthor: Prevent potential UAF in group creation
This commit prevents the possibility of a use after free issue in the GROUP_CREATE ioctl function, which arose as pointer to the group is accessed in that ioctl function after storing it in the Xarray. A malicious userspace can second guess the handle of a group and try to call GROUP_DESTROY ioctl from another thread around the same time as GROUP_CREATE ioctl.
To prevent the use after free exploit, this commit uses a mark on an entry of group pool Xarray which is added just before returning from the GROUP_CREATE ioctl function. The mark is checked for all ioctls that specify the group handle and so userspace won't be abe to delete a group that isn't marked yet.
v2: Add R-bs and fixes tags
CVSS Details
- CVSS 3.1 Base Score: 7.8
- CVSS 3.1 Vector: (CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H)
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Ubuntu | — | Upgrade linux-image-oem-24.04dUpgrade linux-image-6.17.0-1009-aws-64kUpgrade linux-image-raspi-6.17Upgrade linux-image-oracle-64kUpgrade linux-image-realtime-hwe-24.04Upgrade linux-image-virtualUpgrade linux-image-6.17.0-1009-oracle-64kUpgrade linux-image-oem-24.04bUpgrade linux-image-realtimeUpgrade linux-image-gcpUpgrade linux-image-virtual-hwe-24.04Upgrade linux-image-oem-24.04aUpgrade linux-image-generic-hwe-24.04Upgrade linux-image-oracleUpgrade linux-image-realtime-6.17Upgrade linux-image-generic-64kUpgrade linux-image-aws-6.17Upgrade linux-image-aws-64kUpgrade linux-image-virtual-6.17Upgrade linux-image-genericUpgrade linux-image-oem-24.04Upgrade linux-image-6.17.0-1009-oracleUpgrade linux-image-6.17.0-19-genericUpgrade linux-image-6.17.0-1008-realtimeUpgrade linux-image-6.17.0-1017-oemUpgrade linux-image-gcp-64kUpgrade linux-image-azure-6.17Upgrade linux-image-oem-6.17Upgrade linux-image-6.17.0-1009-gcpUpgrade linux-image-6.17.0-19-generic-64kUpgrade linux-image-aws-64k-6.17Upgrade linux-image-oem-24.04cUpgrade linux-image-raspiUpgrade linux-image-azureUpgrade linux-image-6.17.0-1010-raspiUpgrade linux-image-generic-64k-6.17Upgrade linux-image-generic-6.17Upgrade linux-image-generic-64k-hwe-24.04Upgrade linux-image-oracle-6.17Upgrade linux-image-awsUpgrade linux-image-6.17.0-1009-gcp-64kUpgrade linux-image-oracle-64k-6.17Upgrade linux-image-6.17.0-1010-azureUpgrade linux-image-gcp-64k-6.17Upgrade linux-image-gcp-6.17Upgrade linux-image-6.17.0-1009-aws | Mar 17, 2026 | Dec 24, 2025 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub