Use-after-free in Linux kernel - CVE-2026-63884
Published: July 20, 2026
Vulnerability details
The vulnerability allows a local user to cause a denial of service.
The vulnerability exists due to a use-after-free in the i915 TTM object purge logic when purging an object during eviction after validating buffer object placement. A local user can trigger the purge path through crafted GPU memory management operations to cause a denial of service.
The issue was reported under heavy use on DG2 systems and occurs because the associated i915 TTM page vector container may be replaced while the object is still busy.
Affected software
Red Hat Enterprise Linux for x86_64
Red Hat Enterprise Linux for IBM z Systems
Red Hat Enterprise Linux for Power, little endian
Red Hat Enterprise Linux for ARM 64
Red Hat CodeReady Linux Builder for x86_64
Red Hat CodeReady Linux Builder for Power, little endian
Red Hat CodeReady Linux Builder for ARM 64
Red Hat Enterprise Linux for Real Time
Red Hat Enterprise Linux for Real Time for NFV
Ubuntu
kernel (Red Hat package)
kernel-rt-debug (Red Hat package)
kernel-rt-debug-devel (Red Hat package)
kernel-rt-debug-modules-extra (Red Hat package)
kernel-rt-kvm (Red Hat package)
linux-ibm (Ubuntu package)
linux-azure (Ubuntu package)
linux-aws (Ubuntu package)
linux-nvidia (Ubuntu package)
linux-nvidia-bos (Ubuntu package)
How to mitigate CVE-2026-63884
kernel (Red Hat package) - update to 4.18.0-553.156.1.el8_10
kernel-rt-debug (Red Hat package) - update to 4.18.0-553.156.1.rt7.497.el8_10
kernel-rt-debug-devel (Red Hat package) - update to 4.18.0-553.156.1.rt7.497.el8_10
kernel-rt-debug-modules-extra (Red Hat package) - update to 4.18.0-553.156.1.rt7.497.el8_10
kernel-rt-kvm (Red Hat package) - update to 4.18.0-553.156.1.rt7.497.el8_10
linux-ibm (Ubuntu package) - addressed in versions 7.0.0-1008.8, 7.0.0-1010.10
linux-azure (Ubuntu package) - addressed in versions 7.0.0-1009.9, 7.0.0-1010.10
linux-aws (Ubuntu package) - addressed in versions 7.0.0-1009.9, 7.0.0-1015.15
linux-nvidia (Ubuntu package) - addressed in versions 7.0.0-1016.16, 7.0.0-1016.16~24.04.1
linux-nvidia-bos (Ubuntu package) - update to 7.0.0-2016.16
External References
- https://git.kernel.org/stable/c/073bcbc95e9648c976da1654c7590a8d6ee12c2d
- https://git.kernel.org/stable/c/28b22dbaf407598cb3bb1d2c586a6f8018690ac2
- https://git.kernel.org/stable/c/5c4063c87a619e4df954c179d24628636f5db15f
- https://git.kernel.org/stable/c/a29654d451bbffe63d584a4cf64ad0efce6bcf1c
- https://git.kernel.org/stable/c/c9ae7e7e3bc98615364313b08d7acea5239ded0b
- https://git.kernel.org/stable/c/df73f3bc731af1c39ac5405bc59c4e7c6f8e9117