{"id":"DEBIAN-CVE-2026-80919","details":"In the Linux kernel, the following vulnerability has been resolved:  drm/amdgpu: fix recursive ww_mutex acquire in amdgpu_devcoredump_format  When dumping IB contents from a hung job, amdgpu_devcoredump_format() acquired the VM root PD's reservation via amdgpu_vm_lock_by_pasid() and then, for each IB, called amdgpu_bo_reserve() on the BO backing the IB. Both reservations are reservation_ww_class_mutex objects and neither used a ww_acquire_ctx, which trips lockdep:    WARNING: possible recursive locking detected   --------------------------------------------   kworker/u128:0 is trying to acquire lock:   ffff88838b16e1f0 (reservation_ww_class_mutex){+.+.}-{4:4},     at: amdgpu_devcoredump_format+0x1594/0x23f0 [amdgpu]    but task is already holding lock:   ffff8882f82681f0 (reservation_ww_class_mutex){+.+.}-{4:4},     at: amdgpu_devcoredump_format+0x1594/0x23f0 [amdgpu]     Possible unsafe locking scenario:          CPU0          ----     lock(reservation_ww_class_mutex);     lock(reservation_ww_class_mutex);     *** DEADLOCK ***    May be due to missing lock nesting notation    Workqueue: events_unbound amdgpu_devcoredump_deferred_work [amdgpu]   Call Trace:    __ww_mutex_lock.constprop.0    ww_mutex_lock    amdgpu_bo_reserve    amdgpu_devcoredump_format+0x1594 [amdgpu]    amdgpu_devcoredump_deferred_work+0xea [amdgpu]  The two reservations are on different BOs in the captured trace, so the splat is a lockdep-correctness warning, not an observed deadlock. It becomes a real self-deadlock whenever the IB BO shares its dma_resv with the root PD (the always-valid case, see amdgpu_vm_is_bo_always_valid()): amdgpu_bo_reserve(abo) re-acquires the same ww_mutex without a ticket and blocks forever. With amdgpu.gpu_recovery=0 the timeout handler refires every ~2 s and each invocation produces this splat, drowning the kernel ring buffer.  Now that amdgpu_vm_lock_by_pasid() takes a drm_exec context, move the IB dumping into a separate helper that locks the root PD and every IB BO together in a single drm_exec ticket. DRM_EXEC_IGNORE_DUPLICATES handles IB BOs that share a dma_resv (e.g. always-valid BOs, or two IBs backed by the same BO). Every lock is now a top-level acquire under one ww_acquire_ctx, so the recursive ww_mutex condition is gone, and the per-IB amdgpu_bo_reserve()/amdgpu_bo_unref() dance -- including a BO refcount leak on the amdgpu_bo_reserve() failure path -- is removed.  (cherry picked from commit d6bf4242731219ee08ce54c365631e395486651e)","modified":"2026-09-10T05:02:39.319081352Z","published":"2026-09-09T17:17:47.003Z","upstream":["CVE-2026-80919"],"references":[{"type":"ADVISORY","url":"https://security-tracker.debian.org/tracker/CVE-2026-80919"}],"affected":[{"package":{"name":"linux","ecosystem":"Debian:14","purl":"pkg:deb/debian/linux?arch=source&distro=forky"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"7.1.12-1"}]}],"versions":["6.12.100-1","6.12.101-1","6.12.105-1","6.12.107-1","6.12.38-1","6.12.41-1","6.12.43-1","6.12.43-1~bpo12+1","6.12.48-1","6.12.57-1","6.12.57-1~bpo12+1","6.12.63-1","6.12.63-1~bpo12+1","6.12.69-1","6.12.69-1~bpo12+1","6.12.73-1","6.12.73-1~bpo12+1","6.12.74-1","6.12.74-2","6.12.74-2~bpo12+1","6.12.85-1","6.12.85-1~bpo12+1","6.12.86-1","6.12.86-1~bpo12+1","6.12.88-1","6.12.88-1~bpo12+1","6.12.90-1","6.12.90-1~bpo12+1","6.12.90-2","6.12.90-2~bpo12+1","6.12.94-1","6.12.94-1~bpo12+1","6.12.95-1","6.12.95-1~bpo12+1","6.12.96-1","6.13.10-1~exp1","6.13.11-1~exp1","6.13.2-1~exp1","6.13.3-1~exp1","6.13.4-1~exp1","6.13.5-1~exp1","6.13.6-1~exp1","6.13.7-1~exp1","6.13.8-1~exp1","6.13.9-1~exp1","6.13~rc6-1~exp1","6.13~rc7-1~exp1","6.14.3-1~exp1","6.14.5-1~exp1","6.14.6-1~exp1","6.15-1~exp1","6.15.1-1~exp1","6.15.2-1~exp1","6.15.3-1~exp1","6.15.4-1~exp1","6.15.5-1~exp1","6.15.6-1~exp1","6.15~rc7-1~exp1","6.16-1~exp1","6.16.1-1~exp1","6.16.10-1","6.16.11-1","6.16.12-1","6.16.12-1~bpo13+1","6.16.12-2","6.16.3-1","6.16.3-1~bpo13+1","6.16.5-1","6.16.6-1","6.16.7-1","6.16.8-1","6.16.9-1","6.16~rc7-1~exp1","6.17.10-1","6.17.11-1","6.17.12-1","6.17.13-1","6.17.13-1~bpo13+1","6.17.2-1~exp1","6.17.5-1~exp1","6.17.6-1","6.17.7-1","6.17.7-2","6.17.8-1","6.17.8-1~bpo13+1","6.17.9-1","6.18.1-1~exp1","6.18.10-1","6.18.12-1","6.18.12-1~bpo13+1","6.18.13-1","6.18.14-1","6.18.15-1","6.18.15-1~bpo13+1","6.18.2-1~exp1","6.18.3-1","6.18.5-1","6.18.5-1~bpo13+1","6.18.8-1","6.18.9-1","6.18.9-1~bpo13+1","6.18~rc4-1~exp1","6.18~rc4-1~exp2","6.18~rc5-1~exp1","6.18~rc6-1~exp1","6.18~rc7-1~exp1","6.19-1~exp1","6.19.10-1","6.19.10-1~bpo13+1","6.19.11-1","6.19.11-1~bpo13+1","6.19.12-1","6.19.13-1","6.19.13-1~bpo13+1","6.19.14-1","6.19.14-1~bpo13+1","6.19.2-1~exp1","6.19.3-1~exp1","6.19.4-1~exp1","6.19.5-1~exp1","6.19.6-1","6.19.6-2","6.19.6-2~bpo13+1","6.19.8-1","6.19.8-1~bpo13+1","6.19~rc4-1~exp1","6.19~rc5-1~exp1","6.19~rc6-1~exp1","6.19~rc7-1~exp1","6.19~rc8-1~exp1","7.0-1~exp1","7.0.1-1~exp1","7.0.10-1","7.0.10-1~bpo13+1","7.0.12-1","7.0.12-2","7.0.12-2~bpo13+1","7.0.13-1","7.0.13-1~bpo13+1","7.0.14-1","7.0.3-1","7.0.4-1","7.0.4-1~bpo13+1","7.0.7-1","7.0.7-1~bpo13+1","7.0.9-1","7.0.9-1~bpo13+1","7.1.1-1~exp1","7.1.10-1","7.1.2-1~exp1","7.1.3-1","7.1.3-1+sunvdc","7.1.3-1~bpo13+1","7.1.4-1","7.1.5-1","7.1.6-1","7.1.7-1","7.1.7-1~bpo13+1","7.1.8-1","7.1.8-1~bpo13+1","7.1.8-2","7.1.9-1","7.1.9-1+sparc64","7.1~rc2-1~exp1","7.1~rc3-1~exp1","7.1~rc4-1~exp1","7.1~rc4-1~exp2","7.1~rc5-1~exp1","7.1~rc7-1~exp1"],"ecosystem_specific":{"urgency":"not yet assigned"},"database_specific":{"source":"https://storage.googleapis.com/debian-osv/debian-cve-osv/DEBIAN-CVE-2026-80919.json"}}],"schema_version":"1.9.0"}