Improper Update of Reference Count Affecting kernel-ipaclones-internal package, versions *


Severity

Recommended
0.0
high
0
10

Based on CentOS security rating.

Threat Intelligence

EPSS
0.12% (3rd percentile)

Do your applications use this vulnerable package?

In a few clicks we can analyze your entire application and see what components are vulnerable in your application, and suggest you quick fixes.

Test your applications
  • Snyk IDSNYK-CENTOS8-KERNELIPACLONESINTERNAL-18483408
  • published31 Jul 2026
  • disclosed6 May 2026

Introduced: 6 May 2026

CVE-2026-43237  (opens in a new tab)
CWE-911  (opens in a new tab)

How to fix?

There is no fixed version for Centos:8 kernel-ipaclones-internal.

NVD Description

Note: Versions mentioned in the description apply only to the upstream kernel-ipaclones-internal package and not the kernel-ipaclones-internal package as distributed by Centos. See How to fix? for Centos:8 relevant fixed versions and status.

In the Linux kernel, the following vulnerability has been resolved:

drm/amdgpu: Refactor amdgpu_gem_va_ioctl for Handling Last Fence Update and Timeline Management v4

This commit simplifies the amdgpu_gem_va_ioctl function, key updates include:

  • Moved the logic for managing the last update fence directly into amdgpu_gem_va_update_vm.
  • Introduced checks for the timeline point to enable conditional replacement or addition of fences.

v2: Addressed review comments from Christian. v3: Updated comments (Christian). v4: The previous version selected the fence too early and did not manage its reference correctly, which could lead to stale or freed fences being used. This resulted in refcount underflows and could crash when updating GPU timelines. The fence is now chosen only after the VA mapping work is completed, and its reference is taken safely. After exporting it to the VM timeline syncobj, the driver always drops its local fence reference, ensuring balanced refcounting and avoiding use-after-free on dma_fence.

Crash signature:
[  205.828135] refcount_t: underflow; use-after-free.
[  205.832963] WARNING: CPU: 30 PID: 7274 at lib/refcount.c:28 refcount_warn_saturate+0xbe/0x110
...
[  206.074014] Call Trace:
[  206.076488]  <TASK>
[  206.078608]  amdgpu_gem_va_ioctl+0x6ea/0x740 [amdgpu]
[  206.084040]  ? __pfx_amdgpu_gem_va_ioctl+0x10/0x10 [amdgpu]
[  206.089994]  drm_ioctl_kernel+0x86/0xe0 [drm]
[  206.094415]  drm_ioctl+0x26e/0x520 [drm]
[  206.098424]  ? __pfx_amdgpu_gem_va_ioctl+0x10/0x10 [amdgpu]
[  206.104402]  amdgpu_drm_ioctl+0x4b/0x80 [amdgpu]
[  206.109387]  __x64_sys_ioctl+0x96/0xe0
[  206.113156]  do_syscall_64+0x66/0x2d0
...
[  206.553351] BUG: unable to handle page fault for address: ffffffffc0dfde90
...
[  206.553378] RIP: 0010:dma_fence_signal_timestamp_locked+0x39/0xe0
...
[  206.553405] Call Trace:
[  206.553409]  <IRQ>
[  206.553415]  ? __pfx_drm_sched_fence_free_rcu+0x10/0x10 [gpu_sched]
[  206.553424]  dma_fence_signal+0x30/0x60
[  206.553427]  drm_sched_job_done.isra.0+0x123/0x150 [gpu_sched]
[  206.553434]  dma_fence_signal_timestamp_locked+0x6e/0xe0
[  206.553437]  dma_fence_signal+0x30/0x60
[  206.553441]  amdgpu_fence_process+0xd8/0x150 [amdgpu]
[  206.553854]  sdma_v4_0_process_trap_irq+0x97/0xb0 [amdgpu]
[  206.554353]  edac_mce_amd(E) ee1004(E)
[  206.554270]  amdgpu_irq_dispatch+0x150/0x230 [amdgpu]
[  206.554702]  amdgpu_ih_process+0x6a/0x180 [amdgpu]
[  206.555101]  amdgpu_irq_handler+0x23/0x60 [amdgpu]
[  206.555500]  __handle_irq_event_percpu+0x4a/0x1c0
[  206.555506]  handle_irq_event+0x38/0x80
[  206.555509]  handle_edge_irq+0x92/0x1e0
[  206.555513]  __common_interrupt+0x3e/0xb0
[  206.555519]  common_interrupt+0x80/0xa0
[  206.555525]  </IRQ>
[  206.555527]  <TASK>
...
[  206.555650] RIP: 0010:dma_fence_signal_timestamp_locked+0x39/0xe0
...
[  206.555667] Kernel panic - not syncing: Fatal exception in interrupt

CVSS Base Scores

version 3.1