CVE-2026-43370

HIGH

Linux - Use-After-Free in drm/amdgpu VM Acquire

Title source: llm
STIX 2.1

Description

In the Linux kernel, the following vulnerability has been resolved: drm/amdgpu: Fix use-after-free race in VM acquire Replace non-atomic vm->process_info assignment with cmpxchg() to prevent race when parent/child processes sharing a drm_file both try to acquire the same VM after fork(). (cherry picked from commit c7c573275ec20db05be769288a3e3bb2250ec618)

Scores

CVSS v3 7.8
EPSS 0.0001
EPSS Percentile 2.6%
Attack Vector LOCAL
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

Details

CWE
CWE-416
Status published
Products (28)
Linux/Linux < 4.17
Linux/Linux 1da177e4c3f41524e886b7f1b8a0c1fc7321cac2 - 2c1030f2e84885cc58bffef6af67d5b9d2e7098f
Linux/Linux 1da177e4c3f41524e886b7f1b8a0c1fc7321cac2 - 46d309996bd9251792d7dafdbaf615cf202b4447
Linux/Linux 1da177e4c3f41524e886b7f1b8a0c1fc7321cac2 - 7885eb335d8f9e9942925d57e300a85e3f82ded4
Linux/Linux 1da177e4c3f41524e886b7f1b8a0c1fc7321cac2 - 904025fa8bba1d028adade33346372b4ac1a9249
Linux/Linux 1da177e4c3f41524e886b7f1b8a0c1fc7321cac2 - 94b7782d0c8024f5b88454241c8d4777076c3786
Linux/Linux 1da177e4c3f41524e886b7f1b8a0c1fc7321cac2 - ae87aea330c24f462fc7058ed543ba8bc6798447
Linux/Linux 1da177e4c3f41524e886b7f1b8a0c1fc7321cac2 - c658c1c85ec235b7ecfbf8dbfee385b1332088f4
Linux/Linux 1da177e4c3f41524e886b7f1b8a0c1fc7321cac2 - e61e355cbe49e585097eee28c15b862bfb1c0668
Linux/Linux 4.17
... and 18 more
Published May 08, 2026
Tracked Since May 08, 2026