CVE-2026-93248
In the Linux kernel, the following vulnerability has been resolved:
drm/xe: don't WARN on kernel job timeout when device already wedged
igt@xe_wedged@wedged-at-any-timeout wedges the device in mode 2 (UPON_ANY_HANG_NO_RESET) and then rebinds the driver. During unbind, a GSC proxy kernel submission can still time out; with the device wedged and the GuC CT stopped it can never complete, so its kernel job times out.
Killed queues skip guc_submit_hint_wedged(), leaving 'wedged' false even though the device is already wedged. The timeout handler then treats the kernel queue timeout as unexpected and taints the kernel.
Leer descripción completaMostrar menos
Honour an already-wedged device even for killed queues so the expected teardown timeout no longer trips the WARN.
(cherry picked from commit a1c1dbd0f047bb05de6aaf6abe9103031179bf19)
Detalles técnicos trazas, registros y código del informe original
Tile0: GT1: Kernel-submitted job timed out WARNING: drivers/gpu/drm/xe/xe_guc_submit.c:... at guc_exec_queue_timedout_job() Workqueue: gt-ordered-wq drm_sched_job_timedout
CVSS
NVD no ha asignado puntuación CVSS a esta CVE (habitual desde el cambio de política de abril de 2026).
Probabilidad de explotación (EPSS)
- Probabilidad de explotación en los próximos 30 días: 0.19%
- Percentil entre todas las CVEs puntuadas: 8
- Fecha de la puntuación: 6/10/2026
EPSS (Exploit Prediction Scoring System, de FIRST) estima la probabilidad de que una vulnerabilidad sea explotada en 30 días. Complementa a CVSS (impacto) y a CISA KEV (explotación confirmada).
Tecnologías afectadas (1)
⚠ Inferidas por IA a partir de la descripción — NVD aún no ha analizado esta CVE; no son CPE verificados.
Referencias
JSON original (NVD)
Mostrar
{
"id": "CVE-2026-93248",
"cveTags": [],
"metrics": {},
"affected": [
{
"source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"affectedData": [
{
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"product": "Linux",
"versions": [
{
"status": "affected",
"version": "5a2f117a80c207372513ca8964eeb178874f4990",
"lessThan": "24d81b72992006f9c390f1fc85c7f991e6d06fd6",
"versionType": "git"
},
{
"status": "affected",
"version": "5a2f117a80c207372513ca8964eeb178874f4990",
"lessThan": "13087ad7817e6e5f210064518bfc4d6d58a9c2f3",
"versionType": "git"
}
],
"programFiles": [
"drivers/gpu/drm/xe/xe_guc_submit.c"
],
"defaultStatus": "unaffected"
},
{
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"product": "Linux",
"versions": [
{
"status": "affected",
"version": "6.17"
},
{
"status": "unaffected",
"version": "0",
"lessThan": "6.17",
"versionType": "semver"
},
{
"status": "unaffected",
"version": "7.2.6",
"versionType": "semver",
"lessThanOrEqual": "7.2.*"
},
{
"status": "unaffected",
"version": "7.3-rc1",
"versionType": "original_commit_for_fix",
"lessThanOrEqual": "*"
}
],
"programFiles": [
"drivers/gpu/drm/xe/xe_guc_submit.c"
],
"defaultStatus": "affected"
}
]
}
],
"published": "2026-09-24T16:17:20.963",
"references": [
{
"url": "https://git.kernel.org/stable/c/13087ad7817e6e5f210064518bfc4d6d58a9c2f3",
"source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
},
{
"url": "https://git.kernel.org/stable/c/24d81b72992006f9c390f1fc85c7f991e6d06fd6",
"source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
}
],
"vulnStatus": "Received",
"descriptions": [
{
"lang": "en",
"value": "In the Linux kernel, the following vulnerability has been resolved:\n\ndrm/xe: don't WARN on kernel job timeout when device already wedged\n\nigt@xe_wedged@wedged-at-any-timeout wedges the device in mode 2\n(UPON_ANY_HANG_NO_RESET) and then rebinds the driver. During unbind,\na GSC proxy kernel submission can still time out; with the device wedged\nand the GuC CT stopped it can never complete, so its kernel job times out.\n\n Tile0: GT1: Kernel-submitted job timed out\n WARNING: drivers/gpu/drm/xe/xe_guc_submit.c:...\n\t at guc_exec_queue_timedout_job()\n Workqueue: gt-ordered-wq drm_sched_job_timedout\n\nKilled queues skip guc_submit_hint_wedged(), leaving 'wedged' false even\nthough the device is already wedged. The timeout handler then treats the\nkernel queue timeout as unexpected and taints the kernel.\n\nHonour an already-wedged device even for killed queues so the expected\nteardown timeout no longer trips the WARN.\n\n(cherry picked from commit a1c1dbd0f047bb05de6aaf6abe9103031179bf19)"
}
],
"lastModified": "2026-09-24T16:17:20.963",
"sourceIdentifier": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
}