In the Linux kernel, the following vulnerability has been resolved:
drm/xe/gsc: Fix double-free of managed BO in error path
The error path in xegscinitposthwconfig() explicitly frees a BO allocated with xemanagedbocreatepinmap() via xebounpinmapnovm(). Since the managed BO already has a devm cleanup action registered, this causes a double-free when devm unwinds during probe failure.
Remove the explicit free and let devm handle it, consistent with all other xemanagedbocreatepin_map() callers.
(cherry picked from commit 71d61e3e299a17139e47f980a4d6f425b2c59bf7)
{
"cna_assigner": "Linux",
"osv_generated_from": "https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/64xxx/CVE-2026-64517.json"
}