CyberRota Analysis
AI-GeneratedA race condition vulnerability exists in the Linux kernel's Direct Rendering Manager (DRM) subsystem, specifically in the handling of GEM (Graphics Execution Manager) object handles. This flaw allows a concurrent deletion of an old handle to free the associated GEM object while a new handle is still referencing it, potentially leading to use-after-free errors and system instability. Organizations utilizing Linux systems with graphical applications should prioritize patching this vulnerability to mitigate risks of crashes and exploitation.
Original NVD Description
In the Linux kernel, the following vulnerability has been resolved: drm/gem: fix race between change_handle and handle_delete drm_gem_change_handle_ioctl leaves the old handle live in the IDR during the window between spin_unlock(table_lock) and the final spin_lock(table_lock). A concurrent drm_gem_handle_delete on the old handle succeeds in this window, decrements handle_count to 0, and frees the GEM object while the new handle's IDR entry still references it. NULL the old handle's IDR entry before dropping table_lock so that any concurrent GEM_CLOSE on the old handle sees NULL and returns -EINVAL. Restore the old entry on the prime-bookkeeping error path.