Use-after-free in Linux kernel - CVE-2026-43237
Published: May 7, 2026
Linux kernel
Detailed vulnerability description
The vulnerability allows a local user to cause a denial of service.
The vulnerability exists due to use-after-free in amdgpu_gem_va_ioctl when handling VA mapping updates and GPU timeline management. A local user can trigger the ioctl in a way that causes stale or freed dma_fence objects to be used to cause a denial of service.
The issue can lead to refcount underflows and kernel panic during GPU timeline updates.