CVE-2026-74420
N/A
N/A
Summary
In the Linux kernel, the following vulnerability has been resolved:
drm/gpusvm: Reject VMAs with VM_IO or VM_PFNMAP when creating SVM ranges
VMAs marked with VM_IO or VM_PFNMAP are not backed by struct page objects, which GPUSVM requires in order to operate correctly. In particular, get_pages() relies on hmm_range_fault() to resolve struct pages for the target range.
Attempting to create an SVM range on such VMAs results in repeated get_pages() failures and can lead to an infinite loop inside a driver’s page‑fault handler. Prevent this by rejecting ranges on VM_IO or VM_PFNMAP VMAs and returning -EIO.
Affected Software
| Vendor | Product | Version Range | Status |
|---|---|---|---|
| Linux | Linux | 99624bdff8670795b678eafa6509aaad3a5c0175 < 353f26c74660bcbd8d82cd76622748e14a5a5db3 | affected |
| Linux | Linux | 99624bdff8670795b678eafa6509aaad3a5c0175 < 63f443384979563f16f70420f4fa85bba31238ca | affected |
| Linux | Linux | 99624bdff8670795b678eafa6509aaad3a5c0175 < b82a225e57a334335a21462b75ee2223bc6efe6d | affected |
| Linux | Linux | 6.15 | affected |
| Linux | Linux | 0 < 6.15 | unaffected |
| Linux | Linux | 6.18.40 <= 6.18.* | unaffected |
| Linux | Linux | 7.1.5 <= 7.1.* | unaffected |
| Linux | Linux | 7.2-rc1 <= * | unaffected |
Weaknesses
References
- https://git.kernel.org/stable/c/353f26c74660bcbd8d82cd76622748e14a5a5db3
- https://git.kernel.org/stable/c/63f443384979563f16f70420f4fa85bba31238ca
- https://git.kernel.org/stable/c/b82a225e57a334335a21462b75ee2223bc6efe6d
Feedback
Was this page helpful?
Glad to hear it! Please tell us how we can improve.
Sorry to hear that. Please tell us how we can improve.