Answer in brief
CVE-2026-52976 records a High severity (CVSS 7.8) vulnerability in drm/xe: Fix error cleanup in xe_exec_queue_create_ioctl(). The current sources do not mark it as known exploited. The current feed maps Linux/Linux (generic), Linux/Linux (generic). Check affected ranges and fixed versions before updating.
Analysis pending evidence review
HOL Guard separates source facts from reviewed analysis. See the methodology.
Answer in brief
CVE-2026-52976 records a High severity (CVSS 7.8) vulnerability in drm/xe: Fix error cleanup in xe_exec_queue_create_ioctl(). The current sources do not mark it as known exploited. The current feed maps Linux/Linux (generic), Linux/Linux (generic). Check affected ranges and fixed versions before updating.
Analysis pending evidence review
HOL Guard separates source facts from reviewed analysis. See the methodology.
CVSS is 7.8. The current sources do not mark it as known exploited. Treat this as a source-backed prioritization signal, not a statement about your environment.
Analysis status
Analysis pending evidence review
Factual feed record only; HOL analysis is not approved for indexing. Read the methodology.
The current feed maps Linux/Linux (generic), Linux/Linux (generic). Check affected ranges and fixed versions before updating.
| Package | Affected range | Fixed version |
|---|---|---|
| Linux/Linuxgeneric | >=7970cb36966c9b9183255dc097ae0446300eebcf <f93b00161213a0fe9f7ff1d8498ee5ca9e0a5c43 || >=7970cb36966c9b9183255dc097ae0446300eebcf <753b149d5a433eb19e0c1b0eb4526a6e26120d1f || >=7970cb36966c9b9183255dc097ae0446300eebcf <1be55646d8a2035343b012dcb12210db7bb8b056 || >=7970cb36966c9b9183255dc097ae0446300eebcf <f3cc22d4df3ed58439ea7e21daa54c3608e03b78 | f93b00161213a0fe9f7ff1d8498ee5ca9e0a5c43, 753b149d5a433eb19e0c1b0eb4526a6e26120d1f, 1be55646d8a2035343b012dcb12210db7bb8b056, f3cc22d4df3ed58439ea7e21daa54c3608e03b78 |
| Linux/Linuxgeneric | 6.12 | Not reported |
Published upstream
Jun 24, 2026
Evidence: source:cvelist:source_dates:source-dates:recordSource modified
Aug 5, 2026
Evidence: source:cvelist:source_dates:source-dates:recordFirst seen by HOL
Jun 24, 2026
In the Linux kernel, the following vulnerability has been resolved: drm/xe: Fix error cleanup in xe_exec_queue_create_ioctl() Two error handling issues exist in xe_exec_queue_create_ioctl(): 1. When xe_hw_engine_group_add_exec_queue() fails, the error path jumps to put_exec_queue which skips xe_exec_queue_kill(). If the VM is in preempt fence mode, xe_vm_add_compute_exec_queue() has already added the queue to the VM's compute exec queue list. Skipping the kill leaves the queue on that list, leading to a dangling pointer after the queue is freed. 2. When xa_alloc() fails after xe_hw_engine_group_add_exec_queue() has succeeded, the error path does not call xe_hw_engine_group_del_exec_queue() to remove the queue from the hw engine group list. The queue is then freed while still linked into the hw engine group, causing a use-after-free. Fix both by: - Changing the xe_hw_engine_group_add_exec_queue() failure path to jump to kill_exec_queue so that xe_exec_queue_kill() properly removes the queue from the VM's compute list. - Adding a del_hw_engine_group label before kill_exec_queue for the xa_alloc() failure path, which removes the queue from the hw engine group before proceeding with the rest of the cleanup. (cherry picked from commit 37c831f401746a45d510b312b0ed7a77b1e06ec8)
Quoted source text, attributed separately from HOL analysis.
CVSS is 7.8. The current sources do not mark it as known exploited. Treat this as a source-backed prioritization signal, not a statement about your environment.
Analysis status
Analysis pending evidence review
Factual feed record only; HOL analysis is not approved for indexing. Read the methodology.
The current feed maps Linux/Linux (generic), Linux/Linux (generic). Check affected ranges and fixed versions before updating.
| Package | Affected range | Fixed version |
|---|---|---|
| Linux/Linuxgeneric | >=7970cb36966c9b9183255dc097ae0446300eebcf <f93b00161213a0fe9f7ff1d8498ee5ca9e0a5c43 || >=7970cb36966c9b9183255dc097ae0446300eebcf <753b149d5a433eb19e0c1b0eb4526a6e26120d1f || >=7970cb36966c9b9183255dc097ae0446300eebcf <1be55646d8a2035343b012dcb12210db7bb8b056 || >=7970cb36966c9b9183255dc097ae0446300eebcf <f3cc22d4df3ed58439ea7e21daa54c3608e03b78 | f93b00161213a0fe9f7ff1d8498ee5ca9e0a5c43, 753b149d5a433eb19e0c1b0eb4526a6e26120d1f, 1be55646d8a2035343b012dcb12210db7bb8b056, f3cc22d4df3ed58439ea7e21daa54c3608e03b78 |
| Linux/Linuxgeneric | 6.12 | Not reported |
Published upstream
Jun 24, 2026
Evidence: source:cvelist:source_dates:source-dates:recordSource modified
Aug 5, 2026
Evidence: source:cvelist:source_dates:source-dates:recordFirst seen by HOL
Jun 24, 2026
In the Linux kernel, the following vulnerability has been resolved: drm/xe: Fix error cleanup in xe_exec_queue_create_ioctl() Two error handling issues exist in xe_exec_queue_create_ioctl(): 1. When xe_hw_engine_group_add_exec_queue() fails, the error path jumps to put_exec_queue which skips xe_exec_queue_kill(). If the VM is in preempt fence mode, xe_vm_add_compute_exec_queue() has already added the queue to the VM's compute exec queue list. Skipping the kill leaves the queue on that list, leading to a dangling pointer after the queue is freed. 2. When xa_alloc() fails after xe_hw_engine_group_add_exec_queue() has succeeded, the error path does not call xe_hw_engine_group_del_exec_queue() to remove the queue from the hw engine group list. The queue is then freed while still linked into the hw engine group, causing a use-after-free. Fix both by: - Changing the xe_hw_engine_group_add_exec_queue() failure path to jump to kill_exec_queue so that xe_exec_queue_kill() properly removes the queue from the VM's compute list. - Adding a del_hw_engine_group label before kill_exec_queue for the xa_alloc() failure path, which removes the queue from the hw engine group before proceeding with the rest of the cleanup. (cherry picked from commit 37c831f401746a45d510b312b0ed7a77b1e06ec8)
Quoted source text, attributed separately from HOL analysis.