In the Linux kernel, the following vulnerability has been resolved:
drm/xe/userptr: fix EFAULT handling
Currently we treat EFAULT from hmm_range_fault() as a non-fatal error when called from xe_vm_userptr_pin() with the idea that we want to avoid killing the entire vm and chucking an error, under the assumption that the user just did an unmap or something, and has no intention of actually touching that memory from the GPU. At this point we have already zapped the PTEs so any access should generate a page fault, and if the pin fails there also it will then become fatal.
However it looks like it's possible for the userptr vma to still be on the rebind list in preempt_rebind_work_func(), if we had to retry the pin again due to something happening in the caller before we did the rebind step, but in the meantime needing to re-validate the userptr and this time hitting the EFAULT.
This explains an internal user report of hitting:
[ 191.738349] WARNING: CPU: 1 PID: 157 at drivers/gpu/drm/xe/xe_res_cursor.h:158 xe_pt_stage_bind.constprop.0+0x60a/0x6b0 [xe] [ 191.738551] Workqueue: xe-ordered-wq preempt_rebind_work_func [xe] [ 191.738616] RIP: 0010:xe_pt_stage_bind.constprop.0+0x60a/0x6b0 [xe] [ 191.738690] Call Trace: [ 191.738692] <TASK> [ 191.738694] ? show_regs+0x69/0x80 [ 191.738698] ? __warn+0x93/0x1a0 [ 191.738703] ? xe_pt_stage_bind.constprop.0+0x60a/0x6b0 [xe] [ 191.738759] ? report_bug+0x18f/0x1a0 [ 191.738764] ? handle_bug+0x63/0xa0 [ 191.738767] ? exc_invalid_op+0x19/0x70 [ 191.738770] ? asm_exc_invalid_op+0x1b/0x20 [ 191.738777] ? xe_pt_stage_bind.constprop.0+0x60a/0x6b0 [xe] [ 191.738834] ? ret_from_fork_asm+0x1a/0x30 [ 191.738849] bind_op_prepare+0x105/0x7b0 [xe] [ 191.738906] ? dma_resv_reserve_fences+0x301/0x380 [ 191.738912] xe_pt_update_ops_prepare+0x28c/0x4b0 [xe] [ 191.738966] ? kmemleak_alloc+0x4b/0x80 [ 191.738973] ops_execute+0x188/0x9d0 [xe] [ 191.739036] xe_vm_rebind+0x4ce/0x5a0 [xe] [ 191.739098] ? trace_hardirqs_on+0x4d/0x60 [ 191.739112] preempt_rebind_work_func+0x76f/0xd00 [xe]
Followed by NPD, when running some workload, since the sg was never actually populated but the vma is still marked for rebind when it should be skipped for this special EFAULT case. This is confirmed to fix the user report.
v2 (MattB): - Move earlier. v3 (MattB): - Update the commit message to make it clear that this indeed fixes the issue.
(cherry picked from commit 6b93cb98910c826c2e2004942f8b060311e43618)
CVSS Details
- CVSS 3.1 Base Score: 5.5
- CVSS 3.1 Vector: (CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H)
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Debian | — | Upgrade linux | Jul 23, 2026 | Jul 23, 2026 |
| Redhat_linux | — | No solution exists | Jul 9, 2025 | Mar 27, 2025 |
| Suse | — | Upgrade kernel-obs-buildUpgrade kernel-source-azureUpgrade kernel-kvmsmallUpgrade kernel-azure-vdsoUpgrade kernel-64kbUpgrade kernel-macrosUpgrade kernel-default-livepatchUpgrade kernel-docs-htmlUpgrade kernel-sourceUpgrade kernel-kvmsmall-develUpgrade kernel-syms-azureUpgrade kernel-azure-develUpgrade kernel-default-extraUpgrade kernel-devel-azureUpgrade kernel-kvmsmall-vdsoUpgrade kernel-obs-qaUpgrade kernel-zfcpdumpUpgrade kernel-default-vdsoUpgrade kernel-defaultUpgrade kernel-docsUpgrade kernel-64kb-extraUpgrade kernel-symsUpgrade kernel-source-vanillaUpgrade kernel-develUpgrade kernel-azureUpgrade kernel-64kb-develUpgrade kernel-default-baseUpgrade kernel-default-develUpgrade reiserfs-kmp-defaultUpgrade kernel-azure-extra | Dec 5, 2025 | Jul 8, 2025 |
| Ubuntu | — | Upgrade linux-image-generic-64kUpgrade linux-image-aws-6.8Upgrade linux-image-gkeop-6.8Upgrade linux-image-gkeopUpgrade linux-image-nvidia-6.8Upgrade linux-image-6.8.0-1036-gkeUpgrade linux-image-lowlatency-64k-hwe-22.04Upgrade linux-image-realtime-hwe-22.04Upgrade linux-image-6.8.0-85-genericUpgrade linux-image-6.8.0-1039-nvidia-lowlatency-64kUpgrade linux-image-lowlatency-64kUpgrade linux-image-6.8.0-1039-raspiUpgrade linux-image-oem-22.04aUpgrade linux-image-6.8.0-2031-raspi-realtimeUpgrade linux-image-aws-64kUpgrade linux-image-6.8.0-1039-nvidia-lowlatencyUpgrade linux-image-6.8.0-84-lowlatency-64kUpgrade linux-image-6.8.0-1040-gcpUpgrade linux-image-gkeUpgrade linux-image-6.8.0-1039-awsUpgrade linux-image-ibmUpgrade linux-image-azure-nvidia-lts-24.04Upgrade linux-image-azure-nvidia-6.8Upgrade linux-image-oracle-64k-6.8Upgrade linux-image-genericUpgrade linux-image-oem-22.04cUpgrade linux-image-gke-6.8Upgrade linux-image-6.8.1-1034-realtimeUpgrade linux-image-6.8.0-1036-azureUpgrade linux-image-virtual-6.8Upgrade linux-image-nvidia-lowlatency-6.8Upgrade linux-image-6.8.0-1025-azure-nvidiaUpgrade linux-image-azure-6.8Upgrade linux-image-6.8.0-1039-nvidiaUpgrade linux-image-azure-lts-24.04Upgrade linux-image-nvidiaUpgrade linux-image-6.8.0-1037-ibmUpgrade linux-image-azureUpgrade linux-image-oracle-64k-lts-24.04Upgrade linux-image-lowlatencyUpgrade linux-image-6.8.0-1038-azure-fdeUpgrade linux-image-generic-lpaeUpgrade linux-image-azure-nvidiaUpgrade linux-image-nvidia-64k-hwe-22.04Upgrade linux-image-gcp-64k-lts-24.04Upgrade linux-image-6.8.0-1023-gkeopUpgrade linux-image-raspi-realtime-6.8Upgrade linux-image-raspiUpgrade linux-image-virtual-hwe-22.04Upgrade linux-image-oracle-lts-24.04Upgrade linux-image-ibm-classicUpgrade linux-image-6.8.0-84-genericUpgrade linux-image-realtime-6.8.1Upgrade linux-image-oem-22.04Upgrade linux-image-lowlatency-6.8Upgrade linux-image-azure-fde-lts-24.04Upgrade linux-image-6.8.0-85-generic-64kUpgrade linux-image-gcp-6.8Upgrade linux-image-generic-hwe-22.04Upgrade linux-image-azure-fdeUpgrade linux-image-awsUpgrade linux-image-6.8.0-84-generic-64kUpgrade linux-image-aws-lts-24.04Upgrade linux-image-6.8.0-1039-nvidia-64kUpgrade linux-image-ibm-lts-24.04Upgrade linux-image-6.8.0-1038-azureUpgrade linux-image-gcp-64k-6.8Upgrade linux-image-gcp-lts-24.04Upgrade linux-image-6.8.0-84-lowlatencyUpgrade linux-image-nvidia-64k-6.8Upgrade linux-image-gke-64k-6.8Upgrade linux-image-nvidia-lowlatencyUpgrade linux-image-generic-64k-6.8Upgrade linux-image-gcp-64kUpgrade linux-image-aws-64k-6.8Upgrade linux-image-6.8.0-1039-aws-64kUpgrade linux-image-realtimeUpgrade linux-image-raspi-6.8Upgrade linux-image-oracle-64kUpgrade linux-image-oem-22.04bUpgrade linux-image-gke-64kUpgrade linux-image-6.8.0-1040-gcp-64kUpgrade linux-image-virtualUpgrade linux-image-azure-fde-6.8Upgrade linux-image-6.8.0-1036-gke-64kUpgrade linux-image-oracle-6.8Upgrade linux-image-nvidia-hwe-22.04Upgrade linux-image-lowlatency-64k-6.8Upgrade linux-image-aws-64k-lts-24.04Upgrade linux-image-6.8.0-1037-oracleUpgrade linux-image-ibm-6.8Upgrade linux-image-gcpUpgrade linux-image-raspi-realtimeUpgrade linux-image-6.8.0-1036-azure-fdeUpgrade linux-image-nvidia-lowlatency-64kUpgrade linux-image-kvmUpgrade linux-image-generic-6.8Upgrade linux-image-6.8.0-1037-oracle-64kUpgrade linux-image-nvidia-lowlatency-64k-6.8Upgrade linux-image-oem-22.04dUpgrade linux-image-lowlatency-hwe-22.04Upgrade linux-image-generic-64k-hwe-22.04Upgrade linux-image-oracleUpgrade linux-image-nvidia-64k | Jun 26, 2025 | Mar 27, 2025 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub