drm/xe/sync: Cleanup partially initialized sync on parse failure
Published May 8, 2026
5.5
MEDIUMCVSS 3.1
EPSS 0.16%
Description
xe_sync_entry_parse() can allocate references (syncobj, fence, chain fence, or user fence) before hitting a later failure path. Several of those paths returned directly, leaving partially initialized state and leaking refs.
Route these error paths through a common free_sync label and call xe_sync_entry_cleanup(sync) before returning the error.
(cherry picked from commit f939bdd9207a5d1fc55cced5459858480686ce22)
Affected products
-
- Version StatusaffectedConstraints
- Version StatusaffectedConstraints
- Version StatusaffectedConstraints
- Version StatusaffectedConstraints
- Version
-
- Version 6.8StatusaffectedConstraints-
- Version 0StatusunaffectedConstraints<6.8
- Version 6.12.78StatusunaffectedConstraints<=6.12.*
- Version 6.18.19StatusunaffectedConstraints<=6.18.*
- Version 6.19.9StatusunaffectedConstraints<=6.19.*
- Version 7.0StatusunaffectedConstraints<=*
- Version
Default status is the baseline for the product, each version can override it (e.g. patched versions marked unaffected).
- ≥ 6.8 · < 6.12.78
- ≥ 6.13 · < 6.18.19
- ≥ 6.19 · < 6.19.9
- 7.0
No data.
Red Hat Enterprise Linux 10
kernel
Fix deferred
Red Hat Enterprise Linux 6
kernel
Not affected
Red Hat Enterprise Linux 7
kernel
Not affected
Red Hat Enterprise Linux 7
kernel-rt
Not affected
Red Hat Enterprise Linux 8
kernel
Not affected
Red Hat Enterprise Linux 8
kernel-rt
Not affected
Red Hat Enterprise Linux 9
kernel
Fix deferred
Red Hat Enterprise Linux 9
kernel-rt
Fix deferred
| Product | Package | State | Advisory |
|---|---|---|---|
| Red Hat Enterprise Linux 10 | kernel | Fix deferred | n/a |
| Red Hat Enterprise Linux 6 | kernel | Not affected | n/a |
| Red Hat Enterprise Linux 7 | kernel | Not affected | n/a |
| Red Hat Enterprise Linux 7 | kernel-rt | Not affected | n/a |
| Red Hat Enterprise Linux 8 | kernel | Not affected | n/a |
| Red Hat Enterprise Linux 8 | kernel-rt | Not affected | n/a |
| Red Hat Enterprise Linux 9 | kernel | Fix deferred | n/a |
| Red Hat Enterprise Linux 9 | kernel-rt | Fix deferred | n/a |
No package ranges for this CVE.
Remediation
Red Hat statement
This Moderate flaw in the Linux kernel's `drm/xe/sync` subsystem could lead to a denial of service. The vulnerability arises from incomplete resource cleanup during synchronization entry parsing, potentially causing resource exhaustion. Exploitation requires local access to the system.
Red Hat mitigation
Mitigation for this issue is either not available or the currently available options do not meet the Red Hat Product Security criteria comprising ease of use and deployment, applicability to widespread installation base, or stability.
References (10)
- https://access.redhat.com/security/cve/CVE-2026-43395 Vendor Advisory
- https://bugzilla.redhat.com/show_bug.cgi?id=2468246 Issue Tracking
- https://euvd.enisa.europa.eu/vulnerability/EUVD-2026-28701 Advisory
- https://git.kernel.org/stable/c/1bfd7575092420ba5a0b944953c95b74a5646ff8 Patch
- https://git.kernel.org/stable/c/91c228f96fcfacc2341a58815b1da8c69da94ebb Patch
- https://git.kernel.org/stable/c/af65cd1853599394b94201c08bed7a46717db478 Patch
- https://git.kernel.org/stable/c/f0af63ffa06306f12592cd3919fad6957b425e1b Patch
- https://lore.kernel.org/linux-cve-announce/2026050838-CVE-2026-43395-e92c@gregkh/T
- https://nvd.nist.gov/vuln/detail/CVE-2026-43395
- https://www.cve.org/CVERecord?id=CVE-2026-43395
Change history (0)
No recorded changes yet.