vulnerability

Red Hat: CVE-2025-37869: kernel: drm/xe: Use local fence in error path of xe_migrate_clear (Multiple Advisories)

Severity
6
CVSS
(AV:L/AC:M/Au:S/C:P/I:P/A:C)
Published
May 9, 2025
Added
Jul 9, 2025
Modified
Jan 27, 2026

Description

In the Linux kernel, the following vulnerability has been resolved:

drm/xe: Use local fence in error path of xe_migrate_clear

The intent of the error path in xe_migrate_clear is to wait on locally
generated fence and then return. The code is waiting on m->fence which
could be the local fence but this is only stable under the job mutex
leading to a possible UAF. Fix code to wait on local fence.

(cherry picked from commit 762b7e95362170b3e13a8704f38d5e47eca4ba74)

Solutions

no-fix-redhat-rpm-packageredhat-upgrade-kernelredhat-upgrade-kernel-rt
Title
NEW

Explore Exposure Command

Confidently identify and prioritize exposures from endpoint to cloud with full attack surface visibility and threat-aware risk context.