Overview
About vulnerability
In the Linux kernel, the following vulnerability has been resolved:
drm/xe/hw_engine: Fix double-free of managed BO in error path
The error path in hw_engine_init() explicitly frees a BO allocated with xe_managed_bo_create_pin_map() via xe_bo_unpin_map_no_vm(). Since the managed BO already has a devm cleanup action registered, this causes a double-free when devm unwinds during probe failure.
Remove the explicit free and let devm handle it, consistent with all other xe_managed_bo_create_pin_map() callers.
(cherry picked from commit e459a3bdeb117be496d7f229e2ea1f6c9fe4080b)
Details
- Affected product:
- AlmaLinux 9.2 ESU , Debian 10 ELS , TuxCare 9.6 ESU
- Affected packages:
- kernel @ 5.14.0 (+2 more)