Race condition in Linux kernel - CVE-2026-63885
Published: July 20, 2026
Vulnerability details
The vulnerability allows a local user to cause a denial of service.
The vulnerability exists due to a race condition in drm_gem_change_handle_ioctl and drm_gem_handle_delete in the drm gem handle management code when handling concurrent handle change and handle delete operations. A local user can trigger concurrent operations on a stale handle reference to cause a denial of service.
The issue can result in the GEM object being freed while a new handle reference still points to it.