CVE-2026-98180: drm/msm: RCU-free the scheduler-containing ring and VM objects

Published Oct 6, 2026
·
Updated

In the Linux kernel, the following vulnerability has been resolved:

drm/msm: RCU-free the scheduler-containing ring and VM objects

Both struct msmringbuffer and struct msmgemvm embed a struct drmgpuscheduler. msmringbufferdestroy() and the VM free callback msmgemvmfree() call drmschedfini() on the embedded scheduler and then free the containing object with plain kfree().

drmschedfencegettimelinename() returns fence->sched->name, and the scheduler fence keeps a .release callback so it is not ops-detached on signalling. A finished fence exported to userspace (the submit out-fence, or a VMBIND fence, via syncfile / drmsyncobj) keeps pointing at the embedded scheduler after the ring/VM is freed, so a later gettimelinename() -- reachable unprivileged through SYNCIOCFILEINFO -- dereferences freed slab memory (KASAN slab-use-after-free read).

Per the dma-fence lifetime contract the exporter must keep the data backing a signalled fence alive for an RCU grace period. Free the scheduler-containing objects with kfreercu() instead of kfree().

Patchwork: https://patchwork.freedesktop.org/patch/750234/

Affected Software

1 affected component
Linux Linux kernel

Remediation

Recommended actions to resolve this vulnerability, in priority order.

  1. Compensating control

    In the msm ringbuffer destruction and VM free paths, call drm_sched_fini() on the embedded drm_gpu_scheduler, then free the containing struct msm_ringbuffer and struct msm_gem_vm objects with kfree_rcu() instead of kfree(), so scheduler-backed fences remain valid through an RCU grace period.

Event History

Oct 6, 2026
CVE Published
via MITRE·08:44 AM
Data Sourced
via MITRE·08:44 AM
Description
Data Sourced
via NVD·09:18 AM
Description

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203