{"id":"CVE-2026-80606","summary":"drm/xe/userptr: Hold notifier_lock for write on inject test path","details":"In the Linux kernel, the following vulnerability has been resolved:\n\ndrm/xe/userptr: Hold notifier_lock for write on inject test path\n\nWhen CONFIG_DRM_XE_USERPTR_INVAL_INJECT=y, xe_pt_svm_userptr_pre_commit()\nruns vma_check_userptr() with the svm notifier_lock taken for read. The\ntest injection causes vma_check_userptr() to call\nxe_vma_userptr_force_invalidate(), which feeds into\nxe_vma_userptr_do_inval() with drm_gpusvm_ctx.in_notifier=true. That\nflag tells drm_gpusvm_unmap_pages() the caller already holds\nnotifier_lock for write and only asserts the mode. Because the caller\nactually holds it for read, the assertion fires:\n\n  WARNING: drivers/gpu/drm/drm_gpusvm.c:1669 at \\\n           drm_gpusvm_unmap_pages+0xd4/0x130 [drm_gpusvm_helper]\n  Call Trace:\n   xe_vma_userptr_do_inval+0x40d/0xfd0 [xe]\n   xe_vma_userptr_invalidate_pass1+0x3e6/0x8d0 [xe]\n   xe_vma_userptr_force_invalidate+0xde/0x290 [xe]\n   vma_check_userptr.constprop.0+0x1c6/0x220 [xe]\n   xe_pt_svm_userptr_pre_commit+0x6a3/0xc60 [xe]\n   ...\n   xe_vm_bind_ioctl+0x3a0a/0x4480 [xe]\n\nAcquire notifier_lock for write in pre-commit when the inject Kconfig\nis enabled, via new helpers xe_pt_svm_userptr_notifier_lock()/_unlock().\nRename xe_svm_assert_held_read() to\nxe_svm_assert_held_read_or_inject_write() so it asserts the correct\nmode under each build configuration. Production builds\n(CONFIG_DRM_XE_USERPTR_INVAL_INJECT=n) keep the existing read-mode\nbehavior bit-for-bit.\n\n(cherry picked from commit 80ccbd97ffee8ad2e73167d826fe7be548364365)","modified":"2026-08-30T03:48:20.917612163Z","published":"2026-08-28T06:48:30.960Z","database_specific":{"cna_assigner":"Linux","osv_generated_from":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/80xxx/CVE-2026-80606.json"},"references":[{"type":"WEB","url":"https://git.kernel.org/stable/c/ab9ea5c943c7e780124e75b7ffad9f1c752b2579"},{"type":"WEB","url":"https://git.kernel.org/stable/c/dca6e08c923a44d2d66b955e03dd57a3a38c2b94"},{"type":"WEB","url":"https://git.kernel.org/stable/c/f9a9abd7bbdab3dfe1b1155e1457dc02b5e14ea5"},{"type":"ADVISORY","url":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/80xxx/CVE-2026-80606.json"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-80606"},{"type":"PACKAGE","url":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git"}],"affected":[{"ranges":[{"type":"GIT","repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","events":[{"introduced":"9e978741488261e117bb50e5dfcf8e4080990958"},{"fixed":"f9a9abd7bbdab3dfe1b1155e1457dc02b5e14ea5"},{"fixed":"ab9ea5c943c7e780124e75b7ffad9f1c752b2579"},{"fixed":"dca6e08c923a44d2d66b955e03dd57a3a38c2b94"}]}],"database_specific":{"source":"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-80606.json"}},{"package":{"name":"Kernel","ecosystem":"Linux"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"6.18.0"},{"fixed":"6.18.40"}]},{"type":"ECOSYSTEM","events":[{"introduced":"6.19.0"},{"fixed":"7.1.5"}]}],"database_specific":{"source":"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-80606.json"}}],"schema_version":"1.9.0","severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:C/C:H/I:H/A:H"}]}