CVE-2026-63885

Source
https://cve.org/CVERecord?id=CVE-2026-63885
Import Source
https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-63885.json
JSON Data
https://api.osv.dev/v1/vulns/CVE-2026-63885
Downstream
Published
2026-07-19T14:54:58.590Z
Modified
2026-07-21T03:47:31.634476730Z
Severity
  • 8.8 (High) CVSS_V3 - CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H CVSS Calculator
Summary
drm/gem: fix race between change_handle and handle_delete
Details

In the Linux kernel, the following vulnerability has been resolved:

drm/gem: fix race between changehandle and handledelete

drmgemchangehandleioctl leaves the old handle live in the IDR during the window between spinunlock(tablelock) and the final spinlock(tablelock). A concurrent drmgemhandledelete on the old handle succeeds in this window, decrements handlecount to 0, and frees the GEM object while the new handle's IDR entry still references it.

NULL the old handle's IDR entry before dropping tablelock so that any concurrent GEMCLOSE on the old handle sees NULL and returns -EINVAL. Restore the old entry on the prime-bookkeeping error path.

Database specific
{
    "osv_generated_from": "https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/63xxx/CVE-2026-63885.json",
    "cna_assigner": "Linux"
}
References

Affected packages

Git / git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git

Affected ranges

Type
GIT
Repo
https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git
Events
Introduced
672464dd53231509c9c771110798c56d4660e19e
Fixed
0dfa42cfe4dbe114533480503934f43e33c1e83d
Type
GIT
Repo
https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git
Events
Introduced
61bd96d3e5472c253f9c1ab77608f0c8aaa9d025
Fixed
cde2c9257cbe8463b9dcf7b1075177b72b5fd938
Type
GIT
Repo
https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git
Events
Introduced
5e28b7b94408897e41c63477aabc9e1db439bc8c
Fixed
7164d78559b0ff29931a366a840a9e5dd53d4b7c

Affected versions

v6.*
v6.18.32
v6.18.33
v6.18.34
v7.*
v7.0.10
v7.0.11
v7.0.9

Database specific

source
"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-63885.json"

Linux / Kernel

Package

Name
Kernel

Affected ranges

Type
ECOSYSTEM
Events
Introduced
6.18.32
Fixed
6.18.35
Type
ECOSYSTEM
Events
Introduced
7.0.9
Fixed
7.0.12

Database specific

source
"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-63885.json"