<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<feed xmlns="http://www.w3.org/2005/Atom" xml:lang="en">
  <id>https://cve.radiocsirt.org/rss/recent/all/10</id>
  <title>Most recent entries from all</title>
  <updated>2026-10-07T23:23:01.568382+00:00</updated>
  <author>
    <name>Vulnerability-Lookup</name>
    <email>csirt@opendfir.org</email>
  </author>
  <link href="https://cve.radiocsirt.org" rel="alternate"/>
  <generator uri="https://lkiesow.github.io/python-feedgen" version="1.0.0">python-feedgen</generator>
  <subtitle>Contains only the most 10 recent entries.</subtitle>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/cve-2025-40096</id>
    <title>CVE-2025-40096 — drm/sched: Fix potential double free in drm_sched_job_add_resv_dependencies</title>
    <updated>2026-10-07T23:23:01.657615+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> Linux</p>
<p>In the Linux kernel, the following vulnerability has been resolved:</p>
<p>drm/sched: Fix potential double free in drm_sched_job_add_resv_dependencies</p>
<p>When adding dependencies with drm_sched_job_add_dependency(), that
function consumes the fence reference both on success and failure, so in
the latter case the dma_fence_put() on the error path (xarray failed to
expand) is a double free.</p>
<p>Interestingly this bug appears to have been present ever since
commit ebd5f74255b9 ("drm/sched: Add dependency tracking"), since the code
back then looked like this:</p>
<p>drm_sched_job_add_implicit_dependencies():
...
       for (i = 0; i &lt; fence_count; i++) {
               ret = drm_sched_job_add_dependency(job, fences[i]);
               if (ret)
                       break;
       }</p>
<p>for (; i &lt; fence_count; i++)
               dma_fence_put(fences[i]);</p>
<p>Which means for the failing 'i' the dma_fence_put was already a double
free. Possibly there were no users at that time, or the test cases were
insufficient to hit it.</p>
<p>The bug was then only noticed and fixed after
commit 9c2ba265352a ("drm/scheduler: use new iterator in drm_sched_job_add_implicit_dependencies v2")
landed, with its fixup of
commit 4eaf02d6076c ("drm/scheduler: fix drm_sched_job_add_implicit_dependencies").</p>
<p>At that point it was a slightly different flavour of a double free, which
commit 963d0b356935 ("drm/scheduler: fix drm_sched_job_add_implicit_dependencies harder")
noticed and attempted to fix.</p>
<p>But it only moved the doub…</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/cve-2025-40096"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/rhsa-2026:0759</id>
    <title>RHSA-2026:0759 — Red Hat Security Advisory: kernel security update</title>
    <updated>2026-10-07T23:23:01.657708+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>kernel: drm/i915: mark requests for GuC virtual engines to avoid use-after-free kernel: smb: client: Fix use-after-free in cifs_fill_dirent kernel: smb: client: let recv_done verify data_offset, data_length and remaining_data_length kernel: drm/sched: Fix potential double free in drm_sched_job_add_resv_dependencies kernel: net: atlantic: fix fragment overflow handling in RX path</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/rhsa-2026:0759"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/rhsa-2026:0760</id>
    <title>RHSA-2026:0760 — Red Hat Security Advisory: kernel-rt security update</title>
    <updated>2026-10-07T23:23:01.657740+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>kernel: drm/i915: mark requests for GuC virtual engines to avoid use-after-free kernel: smb: client: Fix use-after-free in cifs_fill_dirent kernel: smb: client: let recv_done verify data_offset, data_length and remaining_data_length kernel: drm/sched: Fix potential double free in drm_sched_job_add_resv_dependencies kernel: net: atlantic: fix fragment overflow handling in RX path</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/rhsa-2026:0760"/>
  </entry>
</feed>
