CVE-2026-68427
N/A
N/A
Summary
In the Linux kernel, the following vulnerability has been resolved:
gpu: host1x: Fix use-after-free in host1x_bo_clear_cached_mappings
__host1x_bo_unpin() drops the last reference to the mapping and frees it, so we can't dereference mapping afterwards. The cache itself outlives the mapping, so use the cache local variable instead.
Affected Software
| Vendor | Product | Version Range | Status |
|---|---|---|---|
| Linux | Linux | 1da177e4c3f41524e886b7f1b8a0c1fc7321cac2 < abeff53233b984571b87582bb588b4b38ef4ea50 | affected |
| Linux | Linux | 1da177e4c3f41524e886b7f1b8a0c1fc7321cac2 < 5b7e5f84d3d4cea10c3764d2da274810a7934228 | affected |
| Linux | Linux | 1da177e4c3f41524e886b7f1b8a0c1fc7321cac2 < 5f4de3c717d34a24d555af581947742980778c02 | affected |
| Linux | Linux | 1da177e4c3f41524e886b7f1b8a0c1fc7321cac2 < b773faa32b0a98c3eb2b50d96de631681e5d1157 | affected |
| Linux | Linux | 1da177e4c3f41524e886b7f1b8a0c1fc7321cac2 < 266cddf7bd0f6c79b6c0633aef742a22bf70265b | affected |
| Linux | Linux | 0 < 6.6.148 | affected |
| Linux | Linux | 0 < 6.12.101 | affected |
| Linux | Linux | 0 < 6.18.42 | affected |
| Linux | Linux | 0 < 7.1.6 | affected |
| Linux | Linux | 6.6.148 <= 6.6.* | unaffected |
| Linux | Linux | 6.12.101 <= 6.12.* | unaffected |
| Linux | Linux | 6.18.42 <= 6.18.* | unaffected |
| Linux | Linux | 7.1.6 <= 7.1.* | unaffected |
| Linux | Linux | 7.2-rc4 <= * | unaffected |
Weaknesses
References
- https://git.kernel.org/stable/c/abeff53233b984571b87582bb588b4b38ef4ea50
- https://git.kernel.org/stable/c/5b7e5f84d3d4cea10c3764d2da274810a7934228
- https://git.kernel.org/stable/c/5f4de3c717d34a24d555af581947742980778c02
- https://git.kernel.org/stable/c/b773faa32b0a98c3eb2b50d96de631681e5d1157
- https://git.kernel.org/stable/c/266cddf7bd0f6c79b6c0633aef742a22bf70265b
Feedback
Was this page helpful?
Glad to hear it! Please tell us how we can improve.
Sorry to hear that. Please tell us how we can improve.