A use-after-free vulnerability was found in the Linux kernel's vmwgfx driver in vmw_execbuf_tie_context. Systems making use of the vmwgfx driver are potentially affected by this flaw. Exploiting the bug would require an attacker to have access to either /dev/dri/card0 or /dev/dri/rendererD128 and be able to issue an ioctl() on the resulting file descriptor. Under certain circumstances a local unprivileged user could use this flaw to crash the system, causing a denial of service. Reference: https://bugzilla.openanolis.cn/show_bug.cgi?id=2075
Created kernel tracking bugs for this issue: Affects: fedora-all [bug 2133496]
This was fixed for Fedora with the 6.1 7 stable kernel update.