« Volver al listado

CVE-2025-68193

Estado: AplazadaSin puntuar—

In the Linux kernel, the following vulnerability has been resolved:

drm/xe/guc: Add devm release action to safely tear down CT

When a buffer object (BO) is allocated with the XE_BO_FLAG_GGTT_INVALIDATE flag, the driver initiates TLB invalidation requests via the CTB mechanism while releasing the BO. However a premature release of the CTB BO can lead to system crashes, as observed in:

Introduce a devm-managed release action during xe_guc_ct_init() and xe_guc_ct_init_post_hwconfig() to ensure proper CTB disablement before resource deallocation, preventing the use-after-free scenario.

Detalles técnicos trazas, registros y código del informe original
Oops: Oops: 0000 [#1] SMP NOPTI
RIP: 0010:h2g_write+0x2f3/0x7c0 [xe]
Call Trace:
 guc_ct_send_locked+0x8b/0x670 [xe]
 xe_guc_ct_send_locked+0x19/0x60 [xe]
 send_tlb_invalidation+0xb4/0x460 [xe]
 xe_gt_tlb_invalidation_ggtt+0x15e/0x2e0 [xe]
 ggtt_invalidate_gt_tlb.part.0+0x16/0x90 [xe]
 ggtt_node_remove+0x110/0x140 [xe]
 xe_ggtt_node_remove+0x40/0xa0 [xe]
 xe_ggtt_remove_bo+0x87/0x250 [xe]

CVSS

NVD no ha asignado puntuación CVSS a esta CVE (habitual desde el cambio de política de abril de 2026).

Probabilidad de explotación (EPSS)

EPSS (Exploit Prediction Scoring System, de FIRST) estima la probabilidad de que una vulnerabilidad sea explotada en 30 días. Complementa a CVSS (impacto) y a CISA KEV (explotación confirmada).

Tecnologías afectadas (1)

⚠ Inferidas por IA a partir de la descripción — NVD aún no ha analizado esta CVE; no son CPE verificados.

Referencias

JSON original (NVD)

Mostrar
{
  "id": "CVE-2025-68193",
  "cveTags": [],
  "metrics": {},
  "affected": [
    {
      "source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
      "affectedData": [
        {
          "repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
          "vendor": "Linux",
          "product": "Linux",
          "versions": [
            {
              "status": "affected",
              "version": "231c4110873a5db4975512c30aa10edcc5be56e2",
              "lessThan": "52faa05fcd9f78af99abebe30a4b7b444744c991",
              "versionType": "git"
            },
            {
              "status": "affected",
              "version": "231c4110873a5db4975512c30aa10edcc5be56e2",
              "lessThan": "ee4b32220a6b41e71512e8804585325e685456ba",
              "versionType": "git"
            }
          ],
          "programFiles": [
            "drivers/gpu/drm/xe/xe_guc.c",
            "drivers/gpu/drm/xe/xe_guc_ct.c",
            "drivers/gpu/drm/xe/xe_guc_ct.h"
          ],
          "defaultStatus": "unaffected"
        },
        {
          "repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
          "vendor": "Linux",
          "product": "Linux",
          "versions": [
            {
              "status": "affected",
              "version": "6.10"
            },
            {
              "status": "unaffected",
              "version": "0",
              "lessThan": "6.10",
              "versionType": "semver"
            },
            {
              "status": "unaffected",
              "version": "6.17.8",
              "versionType": "semver",
              "lessThanOrEqual": "6.17.*"
            },
            {
              "status": "unaffected",
              "version": "6.18",
              "versionType": "original_commit_for_fix",
              "lessThanOrEqual": "*"
            }
          ],
          "programFiles": [
            "drivers/gpu/drm/xe/xe_guc.c",
            "drivers/gpu/drm/xe/xe_guc_ct.c",
            "drivers/gpu/drm/xe/xe_guc_ct.h"
          ],
          "defaultStatus": "affected"
        }
      ]
    }
  ],
  "published": "2025-12-16T14:15:52.020",
  "references": [
    {
      "url": "https://git.kernel.org/stable/c/52faa05fcd9f78af99abebe30a4b7b444744c991",
      "source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
    },
    {
      "url": "https://git.kernel.org/stable/c/ee4b32220a6b41e71512e8804585325e685456ba",
      "source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
    }
  ],
  "vulnStatus": "Deferred",
  "descriptions": [
    {
      "lang": "en",
      "value": "In the Linux kernel, the following vulnerability has been resolved:\n\ndrm/xe/guc: Add devm release action to safely tear down CT\n\nWhen a buffer object (BO) is allocated with the XE_BO_FLAG_GGTT_INVALIDATE\nflag, the driver initiates TLB invalidation requests via the CTB mechanism\nwhile releasing the BO. However a premature release of the CTB BO can lead\nto system crashes, as observed in:\n\nOops: Oops: 0000 [#1] SMP NOPTI\nRIP: 0010:h2g_write+0x2f3/0x7c0 [xe]\nCall Trace:\n guc_ct_send_locked+0x8b/0x670 [xe]\n xe_guc_ct_send_locked+0x19/0x60 [xe]\n send_tlb_invalidation+0xb4/0x460 [xe]\n xe_gt_tlb_invalidation_ggtt+0x15e/0x2e0 [xe]\n ggtt_invalidate_gt_tlb.part.0+0x16/0x90 [xe]\n ggtt_node_remove+0x110/0x140 [xe]\n xe_ggtt_node_remove+0x40/0xa0 [xe]\n xe_ggtt_remove_bo+0x87/0x250 [xe]\n\nIntroduce a devm-managed release action during xe_guc_ct_init() and\nxe_guc_ct_init_post_hwconfig() to ensure proper CTB disablement before\nresource deallocation, preventing the use-after-free scenario."
    }
  ],
  "lastModified": "2026-06-17T09:58:42.890",
  "sourceIdentifier": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
}