The root cause of this vulnerability is that the ioctl$DRM_IOCTL_MODE_DESTROY_DUMB can decrease refcount of *drm_vgem_gem_object *(created in *vgem_gem_dumb_create*) concurrently, and *vgem_gem_dumb_create *will access the freed drm_vgem_gem_object.
| Product | Vendor | Version |
|---|---|---|
| kernel | n/a | < 7e3f1dfb9e21733d7276bc9ccea4daada163f2ba |