PT-2026-106639 · Linux · Linux

CVE-2026-98310

·

Publicado

2026-10-06

·

Atualizado

2026-10-06

Nenhuma

Não há classificações de severidade ou métricas disponíveis. Quando houver, atualizaremos as informações correspondentes na página.
In the Linux kernel, the following vulnerability has been resolved:
drm/xe/shrinker: Take a runtime PM ref before shrinking non-system memory
xe shrinker walk() walks the SYSTEM and TT LRUs without a runtime PM reference. Shrinking a bo outside system memory invalidates its GPU mappings, which needs the device resumed, so while it is runtime suspended the page table zap trips an assert and the TLB invalidation returns -ENODEV:
WARNING: drivers/gpu/drm/xe/xe bo.c:770 at xe bo move notify+0x1fc/0x450 [xe] xe bo shrink+0x20f/0x2b0 [xe] xe shrinker walk+0x174/0x410 [xe] xe shrinker scan+0x10c/0x1e0 [xe] do shrink slab+0x176/0x7e0 drop caches sysctl handler+0x9c/0xf0
Take a reference before walking a memory type other than XE PL SYSTEM and stop there if it cannot be acquired. Reuse the shrinker's existing acquire path, which resumes the device directly where reclaim allows that and otherwise queues the PM worker for a later scan. Stop the walk once the scan target is met, so a satisfied scan does not wake the device. System memory is still reclaimed while the device is suspended.
Gate this on xe device is l2 flush optimized(), the same condition under which xe bo trigger rebind() issues the invalidation for a non-fault-mode vm, so reclaim is unaffected elsewhere. The System CCS copy already has its own reference in xe bo shrink().
Only a non-fault-mode vm can reach this, since a fault-mode vm requires LR mode and that holds a runtime PM reference for the vm's lifetime.
Reproduced with igt@xe madvise@dontneed-before-exec while the GPU is runtime suspended.
v2: simplify needs rpm check. (Matt) retarget Fixes tag since the issue occurs with the non-fault-mode path added by 4e7ebff69aed. v3: handle this in xe shrinker.c instead of xe bo.c (Thomas) v4: stop the walk once the scan target is met. (Sashiko) v5: rebase on the freed page accounting fix. (Sashiko) v6: reuse the shrinker acquire path so runtime pm can be resumed directly instead of always queueing a worker. (Thomas) v7: replace xe pm runtime put() with xe shrinker runtime pm put(). (Thomas)
(cherry picked from commit 628f92b28bf4c371c10207daf6fc4caee0c0db2e)
Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Identificadores relacionados

CVE-2026-98310

Produtos afetados

Linux