In the Linux kernel, the following vulnerability has been resolved:
drm/xe/userptr: fix EFAULT handling
Currently we treat EFAULT from hmm_range_fault() as a non-fatal error when called from xe_vm_userptr_pin() with the idea that we want to avoid killing the entire vm and chucking an error, under the assumption that the user just did an unmap or something, and has no intention of actually touching that memory from the GPU. At this point we have already zapped the PTEs so any access should generate a page fault, and if the pin fails there also it will then become fatal.
However it looks like it's possible for the userptr vma to still be on the rebind list in preempt_rebind_work_func(), if we had to retry the pin again due to something happening in the caller before we did the rebind step, but in the meantime needing to re-validate the userptr and this time hitting the EFAULT.
This explains an internal user report of hitting:
[ 191.738349] WARNING: CPU: 1 PID: 157 at drivers/gpu/drm/xe/xe_res_cursor.h:158 xe_pt_stage_bind.constprop.0+0x60a/0x6b0 [xe] [ 191.738551] Workqueue: xe-ordered-wq preempt_rebind_work_func [xe] [ 191.738616] RIP: 0010:xe_pt_stage_bind.constprop.0+0x60a/0x6b0 [xe] [ 191.738690] Call Trace: [ 191.738692] <TASK> [ 191.738694] ? show_regs+0x69/0x80 [ 191.738698] ? __warn+0x93/0x1a0 [ 191.738703] ? xe_pt_stage_bind.constprop.0+0x60a/0x6b0 [xe] [ 191.738759] ? report_bug+0x18f/0x1a0 [ 191.738764] ? handle_bug+0x63/0xa0 [ 191.738767] ? exc_invalid_op+0x19/0x70 [ 191.738770] ? asm_exc_invalid_op+0x1b/0x20 [ 191.738777] ? xe_pt_stage_bind.constprop.0+0x60a/0x6b0 [xe] [ 191.738834] ? ret_from_fork_asm+0x1a/0x30 [ 191.738849] bind_op_prepare+0x105/0x7b0 [xe] [ 191.738906] ? dma_resv_reserve_fences+0x301/0x380 [ 191.738912] xe_pt_update_ops_prepare+0x28c/0x4b0 [xe] [ 191.738966] ? kmemleak_alloc+0x4b/0x80 [ 191.738973] ops_execute+0x188/0x9d0 [xe] [ 191.739036] xe_vm_rebind+0x4ce/0x5a0 [xe] [ 191.739098] ? trace_hardirqs_on+0x4d/0x60 [ 191.739112] preempt_rebind_work_func+0x76f/0xd00 [xe]
Followed by NPD, when running some workload, since the sg was never actually populated but the vma is still marked for rebind when it should be skipped for this special EFAULT case. This is confirmed to fix the user report.
v2 (MattB): - Move earlier. v3 (MattB): - Update the commit message to make it clear that this indeed fixes the issue.
(cherry picked from commit 6b93cb98910c826c2e2004942f8b060311e43618)
CVSS Details
- CVSS 3.1 Base Score: 5.5
- CVSS 3.1 Vector: (CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H)
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Debian | — | Upgrade linux | Jul 23, 2026 | Jul 23, 2026 |
| Redhat_linux | — | No solution exists | Jul 9, 2025 | Mar 27, 2025 |
| Suse | — | Upgrade kernel-default-vdsoUpgrade kernel-default-develUpgrade kernel-symsUpgrade kernel-azureUpgrade kernel-64kb-develUpgrade reiserfs-kmp-defaultUpgrade kernel-default-baseUpgrade kernel-develUpgrade kernel-azure-extraUpgrade kernel-defaultUpgrade kernel-docsUpgrade kernel-source-vanillaUpgrade kernel-64kb-extraUpgrade kernel-obs-buildUpgrade kernel-source-azureUpgrade kernel-sourceUpgrade kernel-azure-develUpgrade kernel-devel-azureUpgrade kernel-64kbUpgrade kernel-obs-qaUpgrade kernel-kvmsmall-vdsoUpgrade kernel-default-extraUpgrade kernel-azure-vdsoUpgrade kernel-default-livepatchUpgrade kernel-kvmsmall-develUpgrade kernel-zfcpdumpUpgrade kernel-syms-azureUpgrade kernel-macrosUpgrade kernel-kvmsmallUpgrade kernel-docs-html | Dec 5, 2025 | Jul 8, 2025 |
| Ubuntu | — | Upgrade linux-image-oracle-64kUpgrade linux-image-raspi-6.8Upgrade linux-image-gcp-64kUpgrade linux-image-realtimeUpgrade linux-image-6.8.0-85-generic-64kUpgrade linux-image-gcp-64k-6.8Upgrade linux-image-ibm-lts-24.04Upgrade linux-image-6.8.0-1039-aws-64kUpgrade linux-image-6.8.0-84-lowlatencyUpgrade linux-image-aws-64k-6.8Upgrade linux-image-generic-64k-6.8Upgrade linux-image-gke-64kUpgrade linux-image-azure-fde-lts-24.04Upgrade linux-image-gke-64k-6.8Upgrade linux-image-gcp-6.8Upgrade linux-image-gcpUpgrade linux-image-lowlatency-hwe-22.04Upgrade linux-image-nvidia-lowlatency-64k-6.8Upgrade linux-image-6.8.0-1039-nvidia-64kUpgrade linux-image-aws-lts-24.04Upgrade linux-image-gcp-lts-24.04Upgrade linux-image-nvidia-lowlatency-64kUpgrade linux-image-ibm-6.8Upgrade linux-image-6.8.0-1036-azure-fdeUpgrade linux-image-6.8.0-1037-oracle-64kUpgrade linux-image-kvmUpgrade linux-image-generic-6.8Upgrade linux-image-azure-fdeUpgrade linux-image-6.8.0-1037-oracleUpgrade linux-image-6.8.0-84-generic-64kUpgrade linux-image-awsUpgrade linux-image-generic-hwe-22.04Upgrade linux-image-generic-64k-hwe-22.04Upgrade linux-image-azure-fde-6.8Upgrade linux-image-nvidia-64kUpgrade linux-image-oem-22.04dUpgrade linux-image-6.8.0-1040-gcp-64kUpgrade linux-image-virtualUpgrade linux-image-oracleUpgrade linux-image-oracle-6.8Upgrade linux-image-nvidia-hwe-22.04Upgrade linux-image-oem-22.04bUpgrade linux-image-aws-64k-lts-24.04Upgrade linux-image-nvidia-64k-6.8Upgrade linux-image-nvidia-lowlatencyUpgrade linux-image-lowlatency-64k-6.8Upgrade linux-image-raspi-realtimeUpgrade linux-image-6.8.0-1036-gke-64kUpgrade linux-image-6.8.0-1038-azureUpgrade linux-image-aws-64kUpgrade linux-image-realtime-6.8.1Upgrade linux-image-azure-6.8Upgrade linux-image-oem-22.04Upgrade linux-image-lowlatencyUpgrade linux-image-generic-lpaeUpgrade linux-image-6.8.0-1039-nvidiaUpgrade linux-image-nvidia-lowlatency-6.8Upgrade linux-image-6.8.0-1025-azure-nvidiaUpgrade linux-image-raspi-realtime-6.8Upgrade linux-image-oracle-64k-lts-24.04Upgrade linux-image-lowlatency-6.8Upgrade linux-image-azure-lts-24.04Upgrade linux-image-virtual-6.8Upgrade linux-image-azure-nvidia-lts-24.04Upgrade linux-image-6.8.0-1040-gcpUpgrade linux-image-ibm-classicUpgrade linux-image-nvidia-6.8Upgrade linux-image-lowlatency-64k-hwe-22.04Upgrade linux-image-lowlatency-64kUpgrade linux-image-gkeopUpgrade linux-image-generic-64kUpgrade linux-image-azure-nvidia-6.8Upgrade linux-image-6.8.0-85-genericUpgrade linux-image-6.8.0-1039-nvidia-lowlatency-64kUpgrade linux-image-realtime-hwe-22.04Upgrade linux-image-6.8.0-1039-raspiUpgrade linux-image-nvidiaUpgrade linux-image-6.8.0-84-lowlatency-64kUpgrade linux-image-6.8.0-2031-raspi-realtimeUpgrade linux-image-6.8.0-1039-nvidia-lowlatencyUpgrade linux-image-6.8.0-1039-awsUpgrade linux-image-ibmUpgrade linux-image-azureUpgrade linux-image-6.8.0-1037-ibmUpgrade linux-image-6.8.0-1023-gkeopUpgrade linux-image-gkeUpgrade linux-image-gke-6.8Upgrade linux-image-virtual-hwe-22.04Upgrade linux-image-raspiUpgrade linux-image-oracle-lts-24.04Upgrade linux-image-oracle-64k-6.8Upgrade linux-image-oem-22.04cUpgrade linux-image-gkeop-6.8Upgrade linux-image-genericUpgrade linux-image-6.8.0-1036-gkeUpgrade linux-image-6.8.0-84-genericUpgrade linux-image-aws-6.8Upgrade linux-image-6.8.0-1036-azureUpgrade linux-image-6.8.1-1034-realtimeUpgrade linux-image-azure-nvidiaUpgrade linux-image-nvidia-64k-hwe-22.04Upgrade linux-image-gcp-64k-lts-24.04Upgrade linux-image-6.8.0-1038-azure-fdeUpgrade linux-image-oem-22.04a | Jun 26, 2025 | Mar 27, 2025 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub