Use-after-free in Linux kernel - CVE-2026-68273
Published: August 12, 2026
Vulnerability details
The vulnerability allows a local user to cause a denial of service.
The vulnerability exists due to use-after-free and NULL pointer dereference in the amdgpu context pstate handling code when initializing or finalizing GPU contexts while stable pstate state changes are processed. A local user can create and tear down crafted contexts to cause a denial of service.
The issue arises because context pstate ownership transitions were not consistently protected by the stable_pstate_ctx_lock, and sysfs-triggered state changes can race with context handling.
Affected software
Debian Linux
linux (Debian package)
How to mitigate CVE-2026-68273
linux (Debian package) - update to 6.12.105-1