SEPTEMBER 8, 2026
Live Feed
Back to database
Case File

CVE-2026-63885

HIGH · CVSS 8.8 EPSS 0.16%

Source: NVD + CISA KEV + EPSS · Published 2026-07-19 · Last synced 2026-08-18

CyberRota Analysis

AI-Generated

A race condition vulnerability exists in the Linux kernel's Direct Rendering Manager (DRM) subsystem, specifically in the handling of GEM (Graphics Execution Manager) object handles. This flaw allows a concurrent deletion of an old handle to free the associated GEM object while a new handle is still referencing it, potentially leading to use-after-free errors and system instability. Organizations utilizing Linux systems with graphical applications should prioritize patching this vulnerability to mitigate risks of crashes and exploitation.

CVE
CVE-2026-63885
Severity
HIGH
CVSS
8.8
EPSS
0.16%
Linux

Original NVD Description

In the Linux kernel, the following vulnerability has been resolved: drm/gem: fix race between change_handle and handle_delete drm_gem_change_handle_ioctl leaves the old handle live in the IDR during the window between spin_unlock(table_lock) and the final spin_lock(table_lock). A concurrent drm_gem_handle_delete on the old handle succeeds in this window, decrements handle_count to 0, and frees the GEM object while the new handle's IDR entry still references it. NULL the old handle's IDR entry before dropping table_lock so that any concurrent GEM_CLOSE on the old handle sees NULL and returns -EINVAL. Restore the old entry on the prime-bookkeeping error path.