Impact
The Linux kernel DRM Xe scheduler component holds a pointer to a scheduler timeline name that is freed with the exec queue while scheduler fences still reference it, creating a use‑after‑free condition that can corrupt kernel memory.
Affected Systems
All Linux kernel builds that include the drm/xe/guc driver before commit 41075f0eb5dcbd3b065d15f15ef7bbe9315188e8 are potentially affected; distribution kernels lacking this patch are at risk.
Risk and Exploitability
The CVSS score of 7.8 indicates moderate severity, and the EPSS score of <1% reflects a low probability of exploitation. The vulnerability is not listed in the CISA KEV catalog. Attackers likely need local access to send crafted commands to the DRM Xe scheduler or trigger a scheduler fence that references the freed pointer; the description does not specify any privileged exploitation or escalation requirement.
OpenCVE Enrichment