Linux Kernel host1x GPU: Use-After-Free in host1x_bo_clear_cached_mappings
CVE-2026-68427 Published on August 10, 2026
gpu: host1x: Fix use-after-free in host1x_bo_clear_cached_mappings
In the Linux kernel, the following vulnerability has been resolved:
gpu: host1x: Fix use-after-free in host1x_bo_clear_cached_mappings
__host1x_bo_unpin() drops the last reference to the mapping and frees
it, so we can't dereference mapping afterwards. The cache itself
outlives the mapping, so use the cache local variable instead.
Products Associated with CVE-2026-68427
Want to know whenever a new CVE is published for Linux Kernel? stack.watch will email you.
Affected Versions
Linux:- Version 1da177e4c3f41524e886b7f1b8a0c1fc7321cac2 and below abeff53233b984571b87582bb588b4b38ef4ea50 is affected.
- Version 1da177e4c3f41524e886b7f1b8a0c1fc7321cac2 and below 5b7e5f84d3d4cea10c3764d2da274810a7934228 is affected.
- Version 1da177e4c3f41524e886b7f1b8a0c1fc7321cac2 and below 5f4de3c717d34a24d555af581947742980778c02 is affected.
- Version 1da177e4c3f41524e886b7f1b8a0c1fc7321cac2 and below b773faa32b0a98c3eb2b50d96de631681e5d1157 is affected.
- Version 1da177e4c3f41524e886b7f1b8a0c1fc7321cac2 and below 266cddf7bd0f6c79b6c0633aef742a22bf70265b is affected.
- Before 6.6.148 is affected.
- Before 6.12.101 is affected.
- Before 6.18.42 is affected.
- Before 7.1.6 is affected.
- Version 6.6.148, <= 6.6.* is unaffected.
- Version 6.12.101, <= 6.12.* is unaffected.
- Version 6.18.42, <= 6.18.* is unaffected.
- Version 7.1.6, <= 7.1.* is unaffected.
- Version 7.2-rc4, <= * is unaffected.