In the Linux kernel, the following vulnerability has been resolved: drm/msm: Fix a fence leak in submit error path In error paths, we could unref the submit without calling drm_sched_entity_push_job(), so msm_job_free() will never get called. Since drm_sched_job_cleanup() will NULL out the s_fence, we can use that to detect this case. Patchwork: https://patchwork.freedesktop.org/patch/653584/
| Product | Vendor | Version |
|---|---|---|
| Linux | Linux | < 16.2R2-S9 |
| Linux | Linux | < 17.1R3 |
| Linux | Linux | x64-based systems |
| Linux | Linux | Version 1607 for 32-bit Systems |