CVE-2026-63885
Race in Linux drm/gem can free GEM objects, enabling kernel corruption or local escalation.
Is CVE-2026-63885 being exploited?
Not confirmed. CVE-2026-63885 does not appear in CISA's Known Exploited Vulnerabilities catalog, which records only exploitation that has been observed and reported publicly. That is evidence of absence of a report, not evidence the flaw is unattacked. EPSS currently estimates a 0.17% probability of exploitation in the next 30 days.
How severe is CVE-2026-63885?
CVE-2026-63885 is rated High with a CVSS score of 8.8. Severity describes how bad exploitation would be, not how likely it is: pair it with exploitation evidence before deciding what to patch first.
Is there a patch for CVE-2026-63885?
Yes. A fix has been recorded for CVE-2026-63885. The vendor advisory is the authority on the exact fixed version — apply it from there rather than from a summary.
What does CVE-2026-63885 affect?
CVE-2026-63885 affects Linux kernel (drm/gem), Systems with GPU/DRM exposed (/dev/dri), Workstations and servers using DRM GPU drivers. Confirm the exact affected versions against the vendor advisory before deciding you are exposed.
What should I do about CVE-2026-63885?
Apply vendor kernel/security updates and reboot GPU systems immediately.
Exploitation status reflects CISA's KEV catalog as we last synced it. Check the catalog directly.
Local race causes GEM object use-after-free; may trigger kernel crash, info leak, or local privilege escalation/arb. kernel code execution.
Immediate action required
- affected>= 672464dd53231509c9c771110798c56d4660e19e and < 0dfa42cfe4dbe114533480503934f43e33c1e83d
- affected>= 61bd96d3e5472c253f9c1ab77608f0c8aaa9d025 and < cde2c9257cbe8463b9dcf7b1075177b72b5fd938
- affected>= 5e28b7b94408897e41c63477aabc9e1db439bc8c and < 7164d78559b0ff29931a366a840a9e5dd53d4b7c
- affected>= 6.18.32 and < 6.18.35
- affected>= 7.0.9 and < 7.0.12
As published in the CVE Program record. A version outside these ranges is not a statement that it is unaffected — vendors sometimes understate a range, and distribution-backported builds carry upstream numbers that do not reflect what was patched into them.