In the Linux kernel, the following vulnerability has been resolved: drm/shmem-helper: Remove another errant put in error path drm_gem_shmem_mmap() doesn't own reference in error code path, resulting in the dma-buf shmem GEM object getting prematurely freed leading to a later use-after-free.
Update Linux/Linux to 684c7372bbd6447c2e86a2a84e97a1478604d21f if you use the affected versions. Test the change in a non-production environment first.
Local check
hol-guard supply-chain scandrm/shmem-helper: Remove another errant put in error path affects Linux/Linux (generic), Linux/Linux (generic). Severity is high. In the Linux kernel, the following vulnerability has been resolved: drm/shmem-helper: Remove another errant put in error path drm_gem_shmem_mmap() doesn't own reference in error code path, resulting in the dma-buf shmem GEM object getting prematurely freed leading to a later use-after-free.
AI coding agents often install or upgrade packages automatically in generic. A high vulnerability in a dependency can be pulled into a project through a normal install or update without a human reviewing the change, expanding the blast radius from a single package to every agent workspace that depends on it.
| Package | Affected range | Fixed version |
|---|---|---|
| Linux/Linuxgeneric | >=f49a51bfdc8ea717c97ccd4cc98b7e6daaa5553a <684c7372bbd6447c2e86a2a84e97a1478604d21f || >=f49a51bfdc8ea717c97ccd4cc98b7e6daaa5553a <5cfb617967b05f8f27e862c97db1fabd8485f4db || >=f49a51bfdc8ea717c97ccd4cc98b7e6daaa5553a <dede8c14a37a7ac458f9add56154a074ed78e7cf || >=f49a51bfdc8ea717c97ccd4cc98b7e6daaa5553a <77d26c824aa5a7e0681ef1d5b75fe538d746addc || >=f49a51bfdc8ea717c97ccd4cc98b7e6daaa5553a <ee9adb7a45516cfa536ca92253d7ae59d56db9e4 || 4655afcf0e3874af03afff8c8704b52350bdba47 || >=5.9.5 <5.10 |
In the Linux kernel, the following vulnerability has been resolved: drm/shmem-helper: Remove another errant put in error path drm_gem_shmem_mmap() doesn't own reference in error code path, resulting in the dma-buf shmem GEM object getting prematurely freed leading to a later use-after-free.
Update Linux/Linux to 684c7372bbd6447c2e86a2a84e97a1478604d21f if you use the affected versions. Test the change in a non-production environment first.
Local check
hol-guard supply-chain scandrm/shmem-helper: Remove another errant put in error path affects Linux/Linux (generic), Linux/Linux (generic). Severity is high. In the Linux kernel, the following vulnerability has been resolved: drm/shmem-helper: Remove another errant put in error path drm_gem_shmem_mmap() doesn't own reference in error code path, resulting in the dma-buf shmem GEM object getting prematurely freed leading to a later use-after-free.
AI coding agents often install or upgrade packages automatically in generic. A high vulnerability in a dependency can be pulled into a project through a normal install or update without a human reviewing the change, expanding the blast radius from a single package to every agent workspace that depends on it.
| Package | Affected range | Fixed version |
|---|---|---|
| Linux/Linuxgeneric | >=f49a51bfdc8ea717c97ccd4cc98b7e6daaa5553a <684c7372bbd6447c2e86a2a84e97a1478604d21f || >=f49a51bfdc8ea717c97ccd4cc98b7e6daaa5553a <5cfb617967b05f8f27e862c97db1fabd8485f4db || >=f49a51bfdc8ea717c97ccd4cc98b7e6daaa5553a <dede8c14a37a7ac458f9add56154a074ed78e7cf || >=f49a51bfdc8ea717c97ccd4cc98b7e6daaa5553a <77d26c824aa5a7e0681ef1d5b75fe538d746addc || >=f49a51bfdc8ea717c97ccd4cc98b7e6daaa5553a <ee9adb7a45516cfa536ca92253d7ae59d56db9e4 || 4655afcf0e3874af03afff8c8704b52350bdba47 || >=5.9.5 <5.10 |
| 684c7372bbd6447c2e86a2a84e97a1478604d21f, 5cfb617967b05f8f27e862c97db1fabd8485f4db, dede8c14a37a7ac458f9add56154a074ed78e7cf, 77d26c824aa5a7e0681ef1d5b75fe538d746addc, ee9adb7a45516cfa536ca92253d7ae59d56db9e4, 5.10 |
| Linux/Linuxgeneric | 5.10 | Not reported |
|---|
Fixed versions are reported by the source feed; confirm compatibility before updating.
Reported by CVE List V5 (cvelist).
HOL Guard can help your team review package activity against supported protection paths.
Explore HOL Guard| 684c7372bbd6447c2e86a2a84e97a1478604d21f, 5cfb617967b05f8f27e862c97db1fabd8485f4db, dede8c14a37a7ac458f9add56154a074ed78e7cf, 77d26c824aa5a7e0681ef1d5b75fe538d746addc, ee9adb7a45516cfa536ca92253d7ae59d56db9e4, 5.10 |
| Linux/Linuxgeneric | 5.10 | Not reported |
|---|
Fixed versions are reported by the source feed; confirm compatibility before updating.
Reported by CVE List V5 (cvelist).
HOL Guard can help your team review package activity against supported protection paths.
Explore HOL Guard