CVE-2026-68245

Summary

In the Linux kernel, the following vulnerability has been resolved:

drm/amdgpu: fix lifetime issue of amdgpu_vm_get_task_info_pasid()

The vm pointer returned from amdgpu_vm_get_vm_from_pasid() is only valid while the lock is still being held. Once xa_unlock_irqrestore is called and returned, the pointer is no longer under lock and is subject to modification. Since, the caller still dereferences vm->task_info in amdgpu_vm_get_task_info_vm() after the lock is removed, this causes a use after unlock problem.

Remove the lifetime issue present in amdgpu_vm_get_task_info_pasid() through removing the amdgpu_vm_get_vm_from_pasid() function from amdgpu_vm.c and making the relevant code inline to hold the lock while it is still in use.

(cherry picked from commit 9d01579f3f868b333acc901815972685989092c7)

Affected Software

VendorProductVersion RangeStatus
LinuxLinux1da177e4c3f41524e886b7f1b8a0c1fc7321cac2 < fe16a7e5336ae888751984e30c451fbf7cfa5df7affected
LinuxLinux1da177e4c3f41524e886b7f1b8a0c1fc7321cac2 < 1173190412fb9d12e7efce76734118d9712ff970affected
LinuxLinux1da177e4c3f41524e886b7f1b8a0c1fc7321cac2 < 5d5fb9124a2bba96a7807086d8fe0f7ce810d546affected
LinuxLinux1da177e4c3f41524e886b7f1b8a0c1fc7321cac2 < 04cc4aa3617b0ed67e859f91f09de5d896a46f3aaffected
LinuxLinux0 < 6.12.101affected
LinuxLinux0 < 6.18.42affected
LinuxLinux0 < 7.1.6affected
LinuxLinux6.12.101 <= 6.12.*unaffected
LinuxLinux6.18.42 <= 6.18.*unaffected
LinuxLinux7.1.6 <= 7.1.*unaffected
LinuxLinux7.2-rc3 <= *unaffected

Weaknesses

References