Database/Kernel, userspace & hypervisor
Linux kernel (drivers/gpu/drm/xe): A batched array of VM_BIND operations could evict other buffer objects belonging to
Impact
A batched array of VM_BIND operations could evict other buffer objects belonging to the same VM while that VM's bind pipeline is still walking them, leaving the pipeline dereferencing objects with no backing resource. A tenant can crash the kernel from an ordinary GPU address-space bind, and the crash lands inside the shared xe bind machinery on the node.
Who can reach it
A tenant container holding /dev/dri/renderD* on an Intel xe GPU submits an array of VM_BIND operations sized to force eviction inside its own VM - no privilege beyond the render node, no display path, no host root. The fallout is a kernel oops on a node other tenants are sharing.
What to do
Boot a kernel carrying the xe_vm eviction-policy fix below. Interim: cap per-tenant VRAM so binds do not push the VM into eviction, and keep panic_on_oops off so a single tenant's oops does not take the whole node with it.
References
Related entries
- Linux kernel (drivers/gpu/drm/xe): A tenant's jobs can occupy the same copy engines the driver needs to service GPUCVE-2024-37026 · Linux kernel (drivers/gpu/drm/xe)Medium
- Linux kernel (drivers/gpu/drm/xe): Same per-client accounting path, different failure - if the fdinfo read drops theCVE-2024-46867 · Linux kernel (drivers/gpu/drm/xe)Medium
- Linux kernel (drivers/gpu/drm/xe): User VM_BIND work is scheduled onto engines that can themselves take page faultsCVE-2024-47729 · Linux kernel (drivers/gpu/drm/xe)Medium
- Linux kernel (drivers/gpu/drm/xe): Passing a sync object that fails fence lookup makes the exec ioctl return toCVE-2024-53086 · Linux kernel (drivers/gpu/drm/xe)Medium
- Linux kernel (drivers/gpu/drm/xe): Every exec ioctl that bails on an input-validation error leaves an exec-queueCVE-2024-53087 · Linux kernel (drivers/gpu/drm/xe)Medium
- Linux kernel (drivers/gpu/drm/xe): The migration copy path falls back to a stack bounce buffer when the tenant's bufferCVE-2025-38690 · Linux kernel (drivers/gpu/drm/xe)Medium
This entry is curated: imported from vendor advisories with machine assistance, not yet individually verified. Confirm against your vendor's advisory before acting, and report anything wrong.