Double free in Linux kernel - CVE-2026-64517
Published: July 27, 2026
Linux kernel
Detailed vulnerability description
The vulnerability allows a local user to cause a denial of service.
The vulnerability exists due to double free in xe_gsc_init_post_hwconfig() in the xe_gsc driver component when handling a probe failure error path. A local user can trigger the vulnerable error path to cause a denial of service.
The issue occurs because a managed buffer object is freed explicitly even though a devm cleanup action is already registered.