{"id":"CVE-2026-93180","summary":"drm/panthor: Fix NPD issue on partial unmap of an evicted BO","details":"In the Linux kernel, the following vulnerability has been resolved:\n\ndrm/panthor: Fix NPD issue on partial unmap of an evicted BO\n\nThis commit fixes the NULL pointer dereference issue that would have\nhappened on the split of GPU mapping due to partial unmap of an evicted\nBO. There is a logic to handle the partial unmap of huge pages when the\nGPU mapping is split. That logic was not being completely skipped for\nthe VMA of an evicted BO and that resulted in a NPD possibility for the\n'bo-\u003ebacking.pages' pointer, which is set to NULL when pages of a\nBO are released on eviction.\n\nFollowing dump was seen when a partial unmap was exercised for an\nevicted BO.\nUnable to handle kernel paging request at virtual address 0000000000002000\nMem abort info:\n  ESR = 0x0000000096000004\n  EC = 0x25: DABT (current EL), IL = 32 bits\n  SET = 0, FnV = 0\n  EA = 0, S1PTW = 0\n  FSC = 0x04: level 0 translation fault\nData abort info:\n  ISV = 0, ISS = 0x00000004, ISS2 = 0x00000000\n  CM = 0, WnR = 0, TnD = 0, TagAccess = 0\n  GCS = 0, Overlay = 0, DirtyBit = 0, Xs = 0\nuser pgtable: 4k pages, 48-bit VAs, pgdp=00000008842e8000\n[0000000000002000] pgd=0000000000000000, p4d=0000000000000000\nInternal error: Oops: 0000000096000004 [#1]  SMP\n\u003csnip\u003e\npstate: 20000005 (nzCv daif -PAN -UAO -TCO -DIT -SSBS BTYPE=--)\npc : iova_mapped_as_huge_page+0x20/0x68 [panthor]\nlr : panthor_gpuva_sm_step_remap+0x39c/0x498 [panthor]\nsp : ffff800086193920\nx29: ffff800086193920 x28: ffff800086193a18 x27: ffff800086193b80\nx26: 0000000000400000 x25: 0000000000810000 x24: 0000000000400000\nx23: ffff000808af1800 x22: 0000000000a00000 x21: ffff800086193a00\nx20: ffff000806fd3f00 x19: 0000000000410000 x18: 00000000ffffffff\nx17: 0000000000000000 x16: 0000000000000000 x15: ffff800083ce2d83\nx14: 0000000000000000 x13: 3120646574636976 x12: 6520303030303138\nx11: 2d30303030313420 x10: ffff8000836e6c80 x9 : ffff80007bfc889c\nx8 : 3fffffffffffefff x7 : ffff8000836e6c80 x6 : 0000000000000000\nx5 : ffff00097ef19088 x4 : 0000000000000000 x3 : 0000000000000000\nx2 : 0000000000010000 x1 : 0000000000000400 x0 : 0000000000000000\nCall trace:\n iova_mapped_as_huge_page+0x20/0x68 [panthor] (P)\n op_remap_cb.isra.0+0x70/0xb0\n __drm_gpuvm_sm_unmap+0xf8/0x1c0\n drm_gpuvm_sm_unmap+0x40/0x60\n panthor_vm_exec_op+0xa0/0x168 [panthor]\n panthor_vm_bind_exec_sync_op+0x8c/0xb8 [panthor]\n panthor_ioctl_vm_bind+0xbc/0x170 [panthor]\n drm_ioctl_kernel+0xc0/0x140\n drm_ioctl+0x20c/0x500\n __arm64_sys_ioctl+0xb4/0x118\n invoke_syscall+0x5c/0x120\n el0_svc_common.constprop.0+0x48/0xf8\n do_el0_svc+0x28/0x40\n el0_svc+0x38/0x128\n el0t_64_sync_handler+0xa0/0xe8\n el0t_64_sync+0x198/0x1a0\nCode: 8b030021 cb020021 f940b800 d34cfc21 (f8617801)\n---[ end trace 0000000000000000 ]---\n\nv2: Fix indentation","modified":"2026-09-18T03:48:44.908614345Z","published":"2026-09-17T16:12:08.005Z","database_specific":{"cna_assigner":"Linux","osv_generated_from":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/93xxx/CVE-2026-93180.json"},"references":[{"type":"PACKAGE","url":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git"},{"type":"WEB","url":"https://git.kernel.org/stable/c/23d41b2e68765ad7095b1424f70c21c281f8a600"},{"type":"WEB","url":"https://git.kernel.org/stable/c/5fb40edc7439b99d001988da63485ca51dbd3550"},{"type":"ADVISORY","url":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/93xxx/CVE-2026-93180.json"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-93180"}],"affected":[{"ranges":[{"type":"GIT","repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","events":[{"introduced":"8e7460eac786c72f48c4e04ce9be692b939428ce"},{"fixed":"23d41b2e68765ad7095b1424f70c21c281f8a600"},{"fixed":"5fb40edc7439b99d001988da63485ca51dbd3550"}]}],"database_specific":{"source":"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-93180.json"}},{"package":{"name":"Kernel","ecosystem":"Linux"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"7.0.0"},{"fixed":"7.2.6"}]}],"database_specific":{"source":"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-93180.json"}}],"schema_version":"1.9.0"}