« Volver al listado

CVE-2026-68102

Estado: RecibidaSin puntuar—

In the Linux kernel, the following vulnerability has been resolved:

drm/amdgpu: fix aperture mapping leak

amdgpu_pci_remove() calls drm_dev_unplug() before invoking the driver fini routines. This causes drm_dev_enter() in amdgpu_ttm_fini() to always return false, so iounmap(aper_base_kaddr) never runs on normal driver unload, leaving an orphaned entry in the x86 PAT interval tree.

On connected_to_cpu hardware, the aperture is mapped write-back (WB) via ioremap_cache(). On reload, IP discovery calls memremap(..., MEMREMAP_WC) over the same range. The WC vs WB conflict causes:

Fix by switching to devres-managed mappings so cleanup is guaranteed regardless of drm_dev_enter() state:

Leer descripción completaMostrar menos

Also remove iounmap(aper_base_kaddr) from amdgpu_device_unmap_mmio() since the mapping is now devres-owned.

v2: Remove redundant x86_64 guard (Lijo)

(cherry picked from commit d871e99879cb5fd1fa798b006b4888887e63a17a)

Detalles técnicos trazas, registros y código del informe original
  ioremap error for 0x..., requested 0x1, got 0x0
  amdgpu: discovery failed: -2

- connected_to_cpu path: devm_memremap(MEMREMAP_WB). For
  IORESOURCE_SYSTEM_RAM ranges this takes the try_ram_remap() shortcut,
  returning __va(offset) from the existing kernel direct map. No new
  ioremap VA or PAT entry is created, so there is nothing to orphan.

- dGPU path: devm_ioremap_wc() registers iounmap() as a devres action,
  guaranteeing cleanup at device_del() time.

CVSS

NVD no ha asignado puntuación CVSS a esta CVE (habitual desde el cambio de política de abril de 2026).

Probabilidad de explotación (EPSS)

EPSS (Exploit Prediction Scoring System, de FIRST) estima la probabilidad de que una vulnerabilidad sea explotada en 30 días. Complementa a CVSS (impacto) y a CISA KEV (explotación confirmada).

Tecnologías afectadas (1)

⚠ Inferidas por IA a partir de la descripción — NVD aún no ha analizado esta CVE; no son CPE verificados.

Referencias

JSON original (NVD)

Mostrar
{
  "id": "CVE-2026-68102",
  "cveTags": [],
  "metrics": {},
  "affected": [
    {
      "source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
      "affectedData": [
        {
          "repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
          "vendor": "Linux",
          "product": "Linux",
          "versions": [
            {
              "status": "affected",
              "version": "9d0af8b4def0de6b734ec8db08e96da0458facb6",
              "lessThan": "67bc3647e418e23dc0d17604bdba634a73de809f",
              "versionType": "git"
            },
            {
              "status": "affected",
              "version": "9d0af8b4def0de6b734ec8db08e96da0458facb6",
              "lessThan": "a343d028ad6c174da8dc6af560c51e6d140a6727",
              "versionType": "git"
            },
            {
              "status": "affected",
              "version": "9d0af8b4def0de6b734ec8db08e96da0458facb6",
              "lessThan": "6405c4e75b3bcf0e72bd7a0ff5f1ed0c475e23aa",
              "versionType": "git"
            },
            {
              "status": "affected",
              "version": "9d0af8b4def0de6b734ec8db08e96da0458facb6",
              "lessThan": "f5988b5c300a32ff751724ffd33d5a8d5873e4a7",
              "versionType": "git"
            },
            {
              "status": "affected",
              "version": "9d0af8b4def0de6b734ec8db08e96da0458facb6",
              "lessThan": "ea772a440d56b285f4d491affac50ecd41f6b402",
              "versionType": "git"
            }
          ],
          "programFiles": [
            "drivers/gpu/drm/amd/amdgpu/amdgpu_device.c",
            "drivers/gpu/drm/amd/amdgpu/amdgpu_ttm.c"
          ],
          "defaultStatus": "unaffected"
        },
        {
          "repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
          "vendor": "Linux",
          "product": "Linux",
          "versions": [
            {
              "status": "affected",
              "version": "5.13"
            },
            {
              "status": "unaffected",
              "version": "0",
              "lessThan": "5.13",
              "versionType": "semver"
            },
            {
              "status": "unaffected",
              "version": "6.6.148",
              "versionType": "semver",
              "lessThanOrEqual": "6.6.*"
            },
            {
              "status": "unaffected",
              "version": "6.12.101",
              "versionType": "semver",
              "lessThanOrEqual": "6.12.*"
            },
            {
              "status": "unaffected",
              "version": "6.18.42",
              "versionType": "semver",
              "lessThanOrEqual": "6.18.*"
            },
            {
              "status": "unaffected",
              "version": "7.1.6",
              "versionType": "semver",
              "lessThanOrEqual": "7.1.*"
            },
            {
              "status": "unaffected",
              "version": "7.2",
              "versionType": "original_commit_for_fix",
              "lessThanOrEqual": "*"
            }
          ],
          "programFiles": [
            "drivers/gpu/drm/amd/amdgpu/amdgpu_device.c",
            "drivers/gpu/drm/amd/amdgpu/amdgpu_ttm.c"
          ],
          "defaultStatus": "affected"
        }
      ]
    }
  ],
  "published": "2026-08-10T13:19:54.840",
  "references": [
    {
      "url": "https://git.kernel.org/stable/c/6405c4e75b3bcf0e72bd7a0ff5f1ed0c475e23aa",
      "source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
    },
    {
      "url": "https://git.kernel.org/stable/c/67bc3647e418e23dc0d17604bdba634a73de809f",
      "source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
    },
    {
      "url": "https://git.kernel.org/stable/c/a343d028ad6c174da8dc6af560c51e6d140a6727",
      "source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
    },
    {
      "url": "https://git.kernel.org/stable/c/ea772a440d56b285f4d491affac50ecd41f6b402",
      "source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
    },
    {
      "url": "https://git.kernel.org/stable/c/f5988b5c300a32ff751724ffd33d5a8d5873e4a7",
      "source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
    }
  ],
  "vulnStatus": "Received",
  "descriptions": [
    {
      "lang": "en",
      "value": "In the Linux kernel, the following vulnerability has been resolved:\n\ndrm/amdgpu: fix aperture mapping leak\n\namdgpu_pci_remove() calls drm_dev_unplug() before invoking the driver\nfini routines. This causes drm_dev_enter() in amdgpu_ttm_fini() to\nalways return false, so iounmap(aper_base_kaddr) never runs on normal\ndriver unload, leaving an orphaned entry in the x86 PAT interval tree.\n\nOn connected_to_cpu hardware, the aperture is mapped write-back (WB) via\nioremap_cache(). On reload, IP discovery calls memremap(..., MEMREMAP_WC)\nover the same range. The WC vs WB conflict causes:\n\n  ioremap error for 0x..., requested 0x1, got 0x0\n  amdgpu: discovery failed: -2\n\nFix by switching to devres-managed mappings so cleanup is guaranteed\nregardless of drm_dev_enter() state:\n\n- connected_to_cpu path: devm_memremap(MEMREMAP_WB). For\n  IORESOURCE_SYSTEM_RAM ranges this takes the try_ram_remap() shortcut,\n  returning __va(offset) from the existing kernel direct map. No new\n  ioremap VA or PAT entry is created, so there is nothing to orphan.\n\n- dGPU path: devm_ioremap_wc() registers iounmap() as a devres action,\n  guaranteeing cleanup at device_del() time.\n\nAlso remove iounmap(aper_base_kaddr) from amdgpu_device_unmap_mmio()\nsince the mapping is now devres-owned.\n\nv2: Remove redundant x86_64 guard (Lijo)\n\n(cherry picked from commit d871e99879cb5fd1fa798b006b4888887e63a17a)"
    }
  ],
  "lastModified": "2026-08-17T05:18:09.540",
  "sourceIdentifier": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
}