« Volver al listado

CVE-2026-72362

Estado: RecibidaSin puntuar—

In the Linux kernel, the following vulnerability has been resolved:

drm/xe/pt: Fix NULL pointer dereference in xe_pt_zap_ptes_entry()

The page-table walk framework may pass a NULL *child pointer for unpopulated entries. xe_pt_zap_ptes_entry() called container_of(*child) before checking for NULL, then dereferenced the result, causing a crash.

Move the container_of() call after a NULL guard, so the function returns early instead of proceeding with an invalid pointer. XE_WARN_ON is kept to help root cause the issue, but we now bail instead of crashing the driver.

v2: Comment that triggering XE_WARN_ON is unexpected behavior (Matt Brost)

Leer descripción completaMostrar menos

(cherry picked from commit b9297d19d9df5d4b6c994648570c5dcd1cac68ff)

CVSS

NVD no ha asignado puntuación CVSS a esta CVE (habitual desde el cambio de política de abril de 2026).

Probabilidad de explotación (EPSS)

EPSS (Exploit Prediction Scoring System, de FIRST) estima la probabilidad de que una vulnerabilidad sea explotada en 30 días. Complementa a CVSS (impacto) y a CISA KEV (explotación confirmada).

Tecnologías afectadas (1)

⚠ Inferidas por IA a partir de la descripción — NVD aún no ha analizado esta CVE; no son CPE verificados.

Referencias

JSON original (NVD)

Mostrar
{
  "id": "CVE-2026-72362",
  "cveTags": [],
  "metrics": {},
  "affected": [
    {
      "source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
      "affectedData": [
        {
          "repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
          "vendor": "Linux",
          "product": "Linux",
          "versions": [
            {
              "status": "affected",
              "version": "dd08ebf6c3525a7ea2186e636df064ea47281987",
              "lessThan": "ff330ce16c846b70164ff0eb544c81219d4c5c08",
              "versionType": "git"
            },
            {
              "status": "affected",
              "version": "dd08ebf6c3525a7ea2186e636df064ea47281987",
              "lessThan": "78b1074966d290d4517f42bc81e13c4349368d12",
              "versionType": "git"
            },
            {
              "status": "affected",
              "version": "dd08ebf6c3525a7ea2186e636df064ea47281987",
              "lessThan": "d94b9922b2ae5ee6e900f8da0bd537b251c6110c",
              "versionType": "git"
            },
            {
              "status": "affected",
              "version": "dd08ebf6c3525a7ea2186e636df064ea47281987",
              "lessThan": "3feeb667197bd58a17f4edfdbcad249ffcb3c864",
              "versionType": "git"
            }
          ],
          "programFiles": [
            "drivers/gpu/drm/xe/xe_pt.c"
          ],
          "defaultStatus": "unaffected"
        },
        {
          "repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
          "vendor": "Linux",
          "product": "Linux",
          "versions": [
            {
              "status": "affected",
              "version": "6.8"
            },
            {
              "status": "unaffected",
              "version": "0",
              "lessThan": "6.8",
              "versionType": "semver"
            },
            {
              "status": "unaffected",
              "version": "6.12.97",
              "versionType": "semver",
              "lessThanOrEqual": "6.12.*"
            },
            {
              "status": "unaffected",
              "version": "6.18.40",
              "versionType": "semver",
              "lessThanOrEqual": "6.18.*"
            },
            {
              "status": "unaffected",
              "version": "7.1.5",
              "versionType": "semver",
              "lessThanOrEqual": "7.1.*"
            },
            {
              "status": "unaffected",
              "version": "7.2",
              "versionType": "original_commit_for_fix",
              "lessThanOrEqual": "*"
            }
          ],
          "programFiles": [
            "drivers/gpu/drm/xe/xe_pt.c"
          ],
          "defaultStatus": "affected"
        }
      ]
    }
  ],
  "published": "2026-08-15T06:22:09.627",
  "references": [
    {
      "url": "https://git.kernel.org/stable/c/3feeb667197bd58a17f4edfdbcad249ffcb3c864",
      "source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
    },
    {
      "url": "https://git.kernel.org/stable/c/78b1074966d290d4517f42bc81e13c4349368d12",
      "source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
    },
    {
      "url": "https://git.kernel.org/stable/c/d94b9922b2ae5ee6e900f8da0bd537b251c6110c",
      "source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
    },
    {
      "url": "https://git.kernel.org/stable/c/ff330ce16c846b70164ff0eb544c81219d4c5c08",
      "source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
    }
  ],
  "vulnStatus": "Received",
  "descriptions": [
    {
      "lang": "en",
      "value": "In the Linux kernel, the following vulnerability has been resolved:\n\ndrm/xe/pt: Fix NULL pointer dereference in xe_pt_zap_ptes_entry()\n\nThe page-table walk framework may pass a NULL *child pointer for\nunpopulated entries. xe_pt_zap_ptes_entry() called container_of(*child)\nbefore checking for NULL, then dereferenced the result, causing a crash.\n\nMove the container_of() call after a NULL guard, so the function returns\nearly instead of proceeding with an invalid pointer. XE_WARN_ON is kept\nto help root cause the issue, but we now bail instead of crashing the\ndriver.\n\nv2: Comment that triggering XE_WARN_ON is unexpected behavior (Matt Brost)\n\n(cherry picked from commit b9297d19d9df5d4b6c994648570c5dcd1cac68ff)"
    }
  ],
  "lastModified": "2026-08-17T06:18:40.400",
  "sourceIdentifier": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
}