Bug 2502408 (CVE-2026-64021) - CVE-2026-64021 kernel: drm/xe/oa: Fix exec_queue leak on width check in stream open
Summary: CVE-2026-64021 kernel: drm/xe/oa: Fix exec_queue leak on width check in strea...
Keywords:
Status: NEW
Alias: CVE-2026-64021
Product: Security Response
Classification: Other
Component: vulnerability
Version: unspecified
Hardware: All
OS: Linux
low
low
Target Milestone: ---
Assignee: Product Security
QA Contact:
URL:
Whiteboard:
Depends On:
Blocks:
TreeView+ depends on / blocked
 
Reported: 2026-07-19 16:06 UTC by OSIDB Bzimport
Modified: 2026-07-22 00:40 UTC (History)
2 users (show)

Fixed In Version:
Clone Of:
Environment:
Last Closed:
Embargoed:


Attachments (Terms of Use)

Description OSIDB Bzimport 2026-07-19 16:06:33 UTC
In the Linux kernel, the following vulnerability has been resolved:

drm/xe/oa: Fix exec_queue leak on width check in stream open

In xe_oa_stream_open_ioctl(), when param.exec_q->width > 1 the
function returns -EOPNOTSUPP directly, skipping the existing
err_exec_q cleanup path. The exec_queue reference obtained by
xe_exec_queue_lookup() is leaked.

The exec queue holds a reference on the xe_file, which is only
dropped during queue teardown. The leaked lookup ref is not on
the file's exec_queue xarray, so file close cannot release it.
This keeps both the exec queue and the file private state pinned
indefinitely.

Jump to err_exec_q instead of returning directly so the reference
is released.

(cherry picked from commit 339fa0be9e4a5d69fa47e91f4a36574224fb478f)


Note You need to log in before you can comment on or make changes to this bug.