Database/Kernel, userspace & hypervisor
Linux kernel (drivers/gpu/drm/xe): Xe built its scatter-gather table from HMM page pointers without holding the
Impact
Xe built its scatter-gather table from HMM page pointers without holding the notifier lock or validating the notifier sequence, so it dereferenced and dirtied struct pages the driver holds no reference to. A tenant that races a munmap or page migration against a userptr GPU mapping makes the driver touch pages that have already moved on to someone else - stale-page reference and corruption of memory the GPU was never entitled to.
Who can reach it
Unprivileged process in a container with /dev/dri/renderD* on an Intel Xe node: register a userptr GPU mapping, then unmap or migrate the backing memory concurrently with the driver's page-fault population path. No display node, no root, and userptr is exposed to any render-node client.
What to do
Boot a kernel with the fix commits below, which builds the sg-table under a validated notifier seqno. Interim: restrict /dev/dri/renderD* to trusted workloads on xe hosts.
References
Related entries
- Linux kernel (drivers/gpu/drm/xe): A GPU TLB invalidation for a very large address range computes its length with aCVE-2025-37761 · Linux kernel (drivers/gpu/drm/xe)High
- Linux kernel (drivers/gpu/drm/xe): The error path of the Xe VRAM clear helper waits on a fence pointer that is onlyCVE-2025-37869 · Linux kernel (drivers/gpu/drm/xe)High
- Linux kernel (drivers/gpu/drm/xe): Xe frees data that its exported dma-fences still point at - notably the timelineCVE-2025-38703 · Linux kernel (drivers/gpu/drm/xe)High
- Linux kernel (drivers/gpu/drm/xe): A tenant that submits a deliberately malformed array bind to the Xe VM_BIND ioctlCVE-2025-38731 · Linux kernel (drivers/gpu/drm/xe)High
- Linux kernel (drivers/gpu/drm/xe): On the migration error path the previous fence is released before the code waits onCVE-2025-39740 · Linux kernel (drivers/gpu/drm/xe)High
- Linux kernel (drivers/gpu/drm/xe): The observation-config ioctl dereferences the config object after releasing the lockCVE-2025-71099 · Linux kernel (drivers/gpu/drm/xe)High
This entry is curated: imported from vendor advisories with machine assistance, not yet individually verified. Confirm against your vendor's advisory before acting, and report anything wrong.