In the Linux kernel, the following vulnerability has been resolved:
drm/xe/userptr: fix EFAULT handling
Currently we treat EFAULT from hmm_range_fault() as a non-fatal error when called from xe_vm_userptr_pin() with the idea that we want to avoid killing the entire vm and chucking an error, under the assumption that the user just did an unmap or something, and has no intention of actually touching that memory from the GPU. At this point we have already zapped the PTEs so any access should generate a page fault, and if the pin fails there also it will then become fatal.
However it looks like it's possible for the userptr vma to still be on the rebind list in preempt_rebind_work_func(), if we had to retry the pin again due to something happening in the caller before we did the rebind step, but in the meantime needing to re-validate the userptr and this time hitting the EFAULT.
This explains an internal user report of hitting:
[ 191.738349] WARNING: CPU: 1 PID: 157 at drivers/gpu/drm/xe/xe_res_cursor.h:158 xe_pt_stage_bind.constprop.0+0x60a/0x6b0 [xe] [ 191.738551] Workqueue: xe-ordered-wq preempt_rebind_work_func [xe] [ 191.738616] RIP: 0010:xe_pt_stage_bind.constprop.0+0x60a/0x6b0 [xe] [ 191.738690] Call Trace: [ 191.738692] <TASK> [ 191.738694] ? show_regs+0x69/0x80 [ 191.738698] ? __warn+0x93/0x1a0 [ 191.738703] ? xe_pt_stage_bind.constprop.0+0x60a/0x6b0 [xe] [ 191.738759] ? report_bug+0x18f/0x1a0 [ 191.738764] ? handle_bug+0x63/0xa0 [ 191.738767] ? exc_invalid_op+0x19/0x70 [ 191.738770] ? asm_exc_invalid_op+0x1b/0x20 [ 191.738777] ? xe_pt_stage_bind.constprop.0+0x60a/0x6b0 [xe] [ 191.738834] ? ret_from_fork_asm+0x1a/0x30 [ 191.738849] bind_op_prepare+0x105/0x7b0 [xe] [ 191.738906] ? dma_resv_reserve_fences+0x301/0x380 [ 191.738912] xe_pt_update_ops_prepare+0x28c/0x4b0 [xe] [ 191.738966] ? kmemleak_alloc+0x4b/0x80 [ 191.738973] ops_execute+0x188/0x9d0 [xe] [ 191.739036] xe_vm_rebind+0x4ce/0x5a0 [xe] [ 191.739098] ? trace_hardirqs_on+0x4d/0x60 [ 191.739112] preempt_rebind_work_func+0x76f/0xd00 [xe]
Followed by NPD, when running some workload, since the sg was never actually populated but the vma is still marked for rebind when it should be skipped for this special EFAULT case. This is confirmed to fix the user report.
v2 (MattB): - Move earlier. v3 (MattB): - Update the commit message to make it clear that this indeed fixes the issue.
(cherry picked from commit 6b93cb98910c826c2e2004942f8b060311e43618)
CVSS Details
- CVSS 3.1 Base Score: 5.5
- CVSS 3.1 Vector: (CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H)
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Debian | — | Upgrade linux | Jul 23, 2026 | Jul 23, 2026 |
| Redhat_linux | — | No solution exists | Jul 9, 2025 | Mar 27, 2025 |
| Suse | — | Upgrade kernel-default-livepatchUpgrade kernel-obs-buildUpgrade kernel-syms-azureUpgrade kernel-source-azureUpgrade kernel-docs-htmlUpgrade kernel-kvmsmallUpgrade kernel-macrosUpgrade kernel-azure-vdsoUpgrade kernel-64kbUpgrade kernel-obs-qaUpgrade kernel-azure-develUpgrade kernel-kvmsmall-develUpgrade kernel-sourceUpgrade kernel-devel-azureUpgrade kernel-kvmsmall-vdsoUpgrade kernel-default-extraUpgrade kernel-zfcpdumpUpgrade kernel-64kb-develUpgrade kernel-source-vanillaUpgrade kernel-docsUpgrade kernel-default-develUpgrade kernel-azureUpgrade kernel-develUpgrade kernel-defaultUpgrade reiserfs-kmp-defaultUpgrade kernel-64kb-extraUpgrade kernel-default-vdsoUpgrade kernel-symsUpgrade kernel-default-baseUpgrade kernel-azure-extra | Dec 5, 2025 | Jul 8, 2025 |
| Ubuntu | — | Upgrade linux-image-gkeUpgrade linux-image-6.8.0-1023-gkeopUpgrade linux-image-azureUpgrade linux-image-6.8.0-84-genericUpgrade linux-image-6.8.0-84-lowlatency-64kUpgrade linux-image-6.8.0-1037-ibmUpgrade linux-image-6.8.0-2031-raspi-realtimeUpgrade linux-image-aws-6.8Upgrade linux-image-ibmUpgrade linux-image-azure-nvidia-lts-24.04Upgrade linux-image-ibm-classicUpgrade linux-image-6.8.0-1040-gcpUpgrade linux-image-6.8.0-1039-nvidia-lowlatencyUpgrade linux-image-aws-64kUpgrade linux-image-nvidiaUpgrade linux-image-6.8.0-1039-awsUpgrade linux-image-nvidia-lowlatency-6.8Upgrade linux-image-genericUpgrade linux-image-virtual-hwe-22.04Upgrade linux-image-gke-6.8Upgrade linux-image-6.8.0-1036-azureUpgrade linux-image-6.8.1-1034-realtimeUpgrade linux-image-oracle-lts-24.04Upgrade linux-image-raspiUpgrade linux-image-oracle-64k-6.8Upgrade linux-image-gkeop-6.8Upgrade linux-image-oem-22.04cUpgrade linux-image-6.8.0-1036-gkeUpgrade linux-image-generic-64kUpgrade linux-image-gkeopUpgrade linux-image-6.8.0-85-genericUpgrade linux-image-nvidia-6.8Upgrade linux-image-azure-lts-24.04Upgrade linux-image-lowlatency-6.8Upgrade linux-image-lowlatency-64k-hwe-22.04Upgrade linux-image-6.8.0-1039-nvidia-lowlatency-64kUpgrade linux-image-6.8.0-1039-nvidiaUpgrade linux-image-oracle-64k-lts-24.04Upgrade linux-image-6.8.0-1025-azure-nvidiaUpgrade linux-image-raspi-realtime-6.8Upgrade linux-image-virtual-6.8Upgrade linux-image-realtime-6.8.1Upgrade linux-image-azure-6.8Upgrade linux-image-6.8.0-1039-raspiUpgrade linux-image-gcp-64k-lts-24.04Upgrade linux-image-6.8.0-1038-azure-fdeUpgrade linux-image-oem-22.04aUpgrade linux-image-azure-nvidiaUpgrade linux-image-lowlatency-64kUpgrade linux-image-nvidia-64k-hwe-22.04Upgrade linux-image-oem-22.04Upgrade linux-image-generic-lpaeUpgrade linux-image-azure-nvidia-6.8Upgrade linux-image-lowlatencyUpgrade linux-image-realtime-hwe-22.04Upgrade linux-image-6.8.0-1039-aws-64kUpgrade linux-image-lowlatency-64k-6.8Upgrade linux-image-virtualUpgrade linux-image-azure-fdeUpgrade linux-image-oracleUpgrade linux-image-raspi-6.8Upgrade linux-image-nvidia-64kUpgrade linux-image-gcp-64k-6.8Upgrade linux-image-6.8.0-1037-oracleUpgrade linux-image-lowlatency-hwe-22.04Upgrade linux-image-6.8.0-1039-nvidia-64kUpgrade linux-image-ibm-6.8Upgrade linux-image-azure-fde-6.8Upgrade linux-image-6.8.0-1040-gcp-64kUpgrade linux-image-6.8.0-1036-gke-64kUpgrade linux-image-nvidia-lowlatency-64kUpgrade linux-image-generic-6.8Upgrade linux-image-6.8.0-1036-azure-fdeUpgrade linux-image-6.8.0-1037-oracle-64kUpgrade linux-image-kvmUpgrade linux-image-nvidia-64k-6.8Upgrade linux-image-aws-64k-lts-24.04Upgrade linux-image-nvidia-hwe-22.04Upgrade linux-image-oem-22.04dUpgrade linux-image-nvidia-lowlatency-64k-6.8Upgrade linux-image-6.8.0-1038-azureUpgrade linux-image-oracle-6.8Upgrade linux-image-gke-64kUpgrade linux-image-gcp-64kUpgrade linux-image-realtimeUpgrade linux-image-oracle-64kUpgrade linux-image-6.8.0-84-generic-64kUpgrade linux-image-raspi-realtimeUpgrade linux-image-generic-64k-hwe-22.04Upgrade linux-image-gcpUpgrade linux-image-ibm-lts-24.04Upgrade linux-image-aws-64k-6.8Upgrade linux-image-azure-fde-lts-24.04Upgrade linux-image-aws-lts-24.04Upgrade linux-image-gcp-lts-24.04Upgrade linux-image-gcp-6.8Upgrade linux-image-6.8.0-85-generic-64kUpgrade linux-image-awsUpgrade linux-image-oem-22.04bUpgrade linux-image-nvidia-lowlatencyUpgrade linux-image-generic-64k-6.8Upgrade linux-image-6.8.0-84-lowlatencyUpgrade linux-image-gke-64k-6.8Upgrade linux-image-generic-hwe-22.04 | Jun 26, 2025 | Mar 27, 2025 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub