CVE-2026-68240
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H
Summary
In the Linux kernel, the following vulnerability has been resolved:
drm/gpusvm: publish dpagemap early to avoid device mapping leak on error
drm_gpusvm_get_pages() only stored the local dpagemap into svm_pages->dpagemap on the success path. If a later page failed (e.g. -EOPNOTSUPP when ctx->allow_mixed is false) and jumped to err_unmap, svm_pages->dpagemap was still NULL, so __drm_gpusvm_unmap_pages() skipped device_unmap() and leaked the device mappings already created.
Assign svm_pages->dpagemap when the first device page is mapped so the err_unmap path can device_unmap() those mappings.
This issue was found by Sashiko AI review.
Affected Software
| Vendor | Product | Version Range | Status |
|---|---|---|---|
| Linux | Linux | f70da6f99d4f40c5f481c92e3b65d5e36eaa6dc9 < e8362523fd1b61712f7d996802f9b5dee545c7e6 | affected |
| Linux | Linux | f70da6f99d4f40c5f481c92e3b65d5e36eaa6dc9 < 72e4fca5529e45b5beebad79d804de442f632324 | affected |
| Linux | Linux | f70da6f99d4f40c5f481c92e3b65d5e36eaa6dc9 < 7f708f51e3955bda0d77a0b67ab9bea6c97fea99 | affected |
| Linux | Linux | 6.18 | affected |
| Linux | Linux | 0 < 6.18 | unaffected |
| Linux | Linux | 6.18.44 <= 6.18.* | unaffected |
| Linux | Linux | 7.1.6 <= 7.1.* | unaffected |
| Linux | Linux | 7.2-rc4 <= * | unaffected |
Weaknesses
References
- https://git.kernel.org/stable/c/e8362523fd1b61712f7d996802f9b5dee545c7e6
- https://git.kernel.org/stable/c/72e4fca5529e45b5beebad79d804de442f632324
- https://git.kernel.org/stable/c/7f708f51e3955bda0d77a0b67ab9bea6c97fea99
Feedback
Was this page helpful?
Glad to hear it! Please tell us how we can improve.
Sorry to hear that. Please tell us how we can improve.