« Volver al listado

CVE-2026-98166

Estado: RecibidaSin puntuar—

In the Linux kernel, the following vulnerability has been resolved:

drm/ttm: fix swapped-out resources never leaving their bulk_move range

ttm_tt_swapout() returns the number of pages swapped out on success and a negative error code on failure; for a populated ttm it never returns zero. Commit b2ed01e7ad3d ("drm/ttm: Fix ttm_bo_swapout() infinite LRU walk on swapout failure") moved the bulk_move bookkeeping in ttm_bo_swapout_cb() under "if (!ret)", so the ttm_resource_del_bulk_move_unevictable() / ttm_resource_move_to_lru_tail() pair is now skipped on every successful swapout. The equivalent change for the shrinker in commit 1d59f36e95f7 ("drm/ttm: Fix ttm_bo_shrink() infinite LRU walk on backup failure") tests "lret > 0", which is what was intended here as well.

Leer descripción completaMostrar menos

Before b2ed01e7ad3d the resource was taken off the bulk_move before the swapout; since then a swapped-out resource stays inside its BO's bulk_move range (and on the manager LRU) although it is unevictable. When it is later freed or the BO leaves the bulk_move (ttm_resource_free(), ttm_bo_set_bulk_move() via amdgpu_vm_bo_del()), ttm_resource_del_bulk_move() skips it because of its !ttm_resource_unevictable() guard, so a range endpoint in pos->first / pos->last is left pointing at freed memory. The next ttm_lru_bulk_move_tail() or ttm_resource_add_bulk_move() on that cursor is a use-after-free, seen as the resv WARN in ttm_lru_bulk_move_add(), "list_del corruption" in ttm_resource_move_to_lru_tail() or a NULL dereference in ttm_resource_manager_next() -- minutes to hours after a hibernation, or at process exit / reboot following one. Samuel Ainsworth's analysis of drm/amd issue 5387 (see Link) identified the dangling cursor; the missing removal at swapout time is the reason it dangles.

Testing the condition for success restores the removal. On an AMD Phoenix APU (ASUS UM3406GA, gfx1103) running suspend-then-hibernate on a 7.0.y stable kernel carrying the backport (Ubuntu 7.0.0-31) the bug crashed 5 of 18 hibernation cycles; a function profile of one hibernation showed 336 ttm_tt_swapout() calls and zero ttm_resource_del_bulk_move_unevictable() calls. With this change the removal happens for every swapped-out resource and 12 further cycles were clean.

CVSS

NVD no ha asignado puntuación CVSS a esta CVE (habitual desde el cambio de política de abril de 2026).

Probabilidad de explotación (EPSS)

EPSS (Exploit Prediction Scoring System, de FIRST) estima la probabilidad de que una vulnerabilidad sea explotada en 30 días. Complementa a CVSS (impacto) y a CISA KEV (explotación confirmada).

Tecnologías afectadas (1)

⚠ Inferidas por IA a partir de la descripción — NVD aún no ha analizado esta CVE; no son CPE verificados.

Referencias

JSON original (NVD)

Mostrar
{
  "id": "CVE-2026-98166",
  "cveTags": [],
  "metrics": {},
  "affected": [
    {
      "source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
      "affectedData": [
        {
          "repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
          "vendor": "Linux",
          "product": "Linux",
          "versions": [
            {
              "status": "affected",
              "version": "b2ed01e7ad3de80333e9b962a44024b094bc0b2b",
              "lessThan": "1169fe8c11ca45e3f91d59a73eb271d0ca8a7fb0",
              "versionType": "git"
            },
            {
              "status": "affected",
              "version": "b2ed01e7ad3de80333e9b962a44024b094bc0b2b",
              "lessThan": "3db7d7d583419f7b1f2e141e36418802dbb25cf8",
              "versionType": "git"
            },
            {
              "status": "affected",
              "version": "0124a09e3e5f5f6080efe9663b27af27933f8382",
              "versionType": "git"
            },
            {
              "status": "affected",
              "version": "7.0.10",
              "lessThan": "7.1",
              "versionType": "semver"
            }
          ],
          "programFiles": [
            "drivers/gpu/drm/ttm/ttm_bo.c"
          ],
          "defaultStatus": "unaffected"
        },
        {
          "repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
          "vendor": "Linux",
          "product": "Linux",
          "versions": [
            {
              "status": "affected",
              "version": "7.1"
            },
            {
              "status": "unaffected",
              "version": "0",
              "lessThan": "7.1",
              "versionType": "semver"
            },
            {
              "status": "unaffected",
              "version": "7.2.8",
              "versionType": "semver",
              "lessThanOrEqual": "7.2.*"
            },
            {
              "status": "unaffected",
              "version": "7.3-rc4",
              "versionType": "original_commit_for_fix",
              "lessThanOrEqual": "*"
            }
          ],
          "programFiles": [
            "drivers/gpu/drm/ttm/ttm_bo.c"
          ],
          "defaultStatus": "affected"
        }
      ]
    }
  ],
  "published": "2026-10-06T09:17:58.033",
  "references": [
    {
      "url": "https://git.kernel.org/stable/c/1169fe8c11ca45e3f91d59a73eb271d0ca8a7fb0",
      "source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
    },
    {
      "url": "https://git.kernel.org/stable/c/3db7d7d583419f7b1f2e141e36418802dbb25cf8",
      "source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
    }
  ],
  "vulnStatus": "Received",
  "descriptions": [
    {
      "lang": "en",
      "value": "In the Linux kernel, the following vulnerability has been resolved:\n\ndrm/ttm: fix swapped-out resources never leaving their bulk_move range\n\nttm_tt_swapout() returns the number of pages swapped out on success and\na negative error code on failure; for a populated ttm it never returns\nzero. Commit b2ed01e7ad3d (\"drm/ttm: Fix ttm_bo_swapout() infinite LRU\nwalk on swapout failure\") moved the bulk_move bookkeeping in\nttm_bo_swapout_cb() under \"if (!ret)\", so the\nttm_resource_del_bulk_move_unevictable() / ttm_resource_move_to_lru_tail()\npair is now skipped on every successful swapout. The equivalent change\nfor the shrinker in commit 1d59f36e95f7 (\"drm/ttm: Fix ttm_bo_shrink()\ninfinite LRU walk on backup failure\") tests \"lret > 0\", which is what\nwas intended here as well.\n\nBefore b2ed01e7ad3d the resource was taken off the bulk_move before the\nswapout; since then a swapped-out resource stays inside its BO's\nbulk_move range (and on the manager LRU) although it is unevictable.\nWhen it is later freed or the BO leaves the bulk_move\n(ttm_resource_free(), ttm_bo_set_bulk_move() via amdgpu_vm_bo_del()),\nttm_resource_del_bulk_move() skips it because of its\n!ttm_resource_unevictable() guard, so a range endpoint in pos->first /\npos->last is left pointing at freed memory. The next\nttm_lru_bulk_move_tail() or ttm_resource_add_bulk_move() on that cursor\nis a use-after-free, seen as the resv WARN in ttm_lru_bulk_move_add(),\n\"list_del corruption\" in ttm_resource_move_to_lru_tail() or a NULL\ndereference in ttm_resource_manager_next() -- minutes to hours after a\nhibernation, or at process exit / reboot following one. Samuel\nAinsworth's analysis of drm/amd issue 5387 (see Link) identified the\ndangling cursor; the missing removal at swapout time is the reason it\ndangles.\n\nTesting the condition for success restores the removal. On an AMD\nPhoenix APU (ASUS UM3406GA, gfx1103) running suspend-then-hibernate on\na 7.0.y stable kernel carrying the backport (Ubuntu 7.0.0-31) the bug\ncrashed 5 of 18 hibernation cycles; a function profile of one\nhibernation showed 336 ttm_tt_swapout() calls and zero\nttm_resource_del_bulk_move_unevictable() calls. With this change the\nremoval happens for every swapped-out resource and 12 further cycles\nwere clean."
    }
  ],
  "lastModified": "2026-10-06T09:17:58.033",
  "sourceIdentifier": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
}