CVE-2026-89815
In the Linux kernel, the following vulnerability has been resolved:
drm/ttm: Drop tt->restore after successful restore
ttm_pool_restore_and_alloc() can successfully complete the restore process via ttm_pool_restore_commit(), but tt->restore is not dropped afterward. As a result, subsequent backup/restore flows observe what appears to be a completed restore, while in reality shmem handles are still installed in tt->pages, leading to the stack trace below.
Fix this by freeing and dropping tt->restore in ttm_pool_restore_and_alloc() upon successful completion of the restore.
Detalles técnicos trazas, registros y código del informe original
20545 [ 309.784531] RIP: 0010:sg_alloc_append_table_from_pages+0x38c/0x490 20547 [ 309.809570] RSP: 0018:ffffc9000623b838 EFLAGS: 00010206 20548 [ 309.814827] RAX: 0000000000001000 RBX: ffff88816e42a160 RCX: 0000000000000000 20549 [ 309.821986] RDX: 0000000000002000 RSI: 0000000000000003 RDI: 0000000000001000 20550 [ 309.829147] RBP: ffff88816e42a168 R08: 0000000000000002 R09: 000000007ffff000 20551 [ 309.836310] R10: ffffc9000623b928 R11: 0000000000000000 R12: 000000007ffff000 20552 [ 309.843471] R13: ffff88815ba5a100 R14: 0000000000000000 R15: 0000000000000001 20553 [ 309.850634] FS: 00007f9ff305e700(0000) GS:ffff888276c94000(0000) knlGS:0000000000000000 20554 [ 309.858749] CS: 0010 DS: 0000 ES: 0000 CR0: 0000000080050033 20555 [ 309.864519] CR2: 00007f9fca701000 CR3: 00000001565e2005 CR4: 0000000008f70ef0 20556 [ 309.871678] PKRU: 55555558 20557 [ 309.874403] Call Trace: 20558 [ 309.876866] <TASK> 20559 [ 309.878988] sg_alloc_table_from_pages_segment+0x60/0x100 20560 [ 309.884415] ? ttm_resource_manager_usage+0x36/0x60 [ttm] 20561 [ 309.889845] ? xe_tt_map_sg+0x7d/0xd0 [xe] 20562 [ 309.894045] xe_tt_map_sg+0x7d/0xd0 [xe] 20563 [ 309.898037] xe_bo_move+0x927/0xaa0 [xe] 20564 [ 309.902029] ttm_bo_handle_move_mem+0xba/0x170 [ttm] 20565 [ 309.907022] ttm_bo_validate+0xbe/0x190 [ttm] 20566 [ 309.911405] xe_bo_validate+0x9a/0x120 [xe] 20567 [ 309.915663] xe_gpuvm_validate+0xd9/0x140 [xe] 20568 [ 309.920206] drm_gpuvm_validate+0x2f0/0x5b0 [drm_gpuvm] 20569 [ 309.925459] ? drm_exec_lock_obj+0x63/0x210 [drm_exec] 20570 [ 309.930627] xe_vm_validate_rebind+0x46/0xb0 [xe] 20571 [ 309.935428] xe_exec_fn+0x20/0x40 [xe] 20572 [ 309.939249] drm_gpuvm_exec_lock+0x78/0xc0 [drm_gpuvm] 20573 [ 309.944410] xe_validation_exec_lock+0x5a/0xa0 [xe] 20574 [ 309.949385] xe_exec_ioctl+0x806/0xc30 [xe] 20575 [ 309.953639] ? ttwu_queue_wakelist+0xd9/0xf0 20576 [ 309.957935] ? __pfx_xe_exec_fn+0x10/0x10 [xe] 20577 [ 309.962449] ? __wake_up_common+0x73/0xa0 20578 [ 309.966482] ? __pfx_xe_exec_ioctl+0x10/0x10 [xe] 20579 [ 309.971263] drm_ioctl_kernel+0xa3/0x100 20580 [ 309.975209] drm_ioctl+0x213/0x440 20581 [ 309.978637] ? __pfx_xe_exec_ioctl+0x10/0x10 [xe] 20582 [ 309.983415] xe_drm_ioctl+0x67/0xd0 [xe] 20583 [ 309.987408] __x64_sys_ioctl+0x7f/0xd0
CVSS
- Versión: 3.1
- Vector: CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
- Puntuación base: 7.8
Probabilidad de explotación (EPSS)
- Probabilidad de explotación en los próximos 30 días: 0.17%
- Percentil entre todas las CVEs puntuadas: 6
- Fecha de la puntuación: 5/10/2026
EPSS (Exploit Prediction Scoring System, de FIRST) estima la probabilidad de que una vulnerabilidad sea explotada en 30 días. Complementa a CVSS (impacto) y a CISA KEV (explotación confirmada).
🎯 Técnicas ATT&CK
Cómo se explota esta vulnerabilidad y qué consigue el atacante, en el lenguaje de MITRE ATT&CK.
- Explotación
T1068Exploitation for Privilege Escalationprivilege escalation75 % - Impacto principal
T1499.004Application or System Exploitationimpact65 % - Impacto secundario
T1561.001Disk Content Wipeimpact55 %
Vulnerability in kernel memory management (TTM/DRM) con acceso local (AV:L, PR:L) permite escalada de privilegios. El fallo de limpieza causa corrupción de estado que resulta en crash (DoS) y potencial manipulación de datos en memoria de GPU.
Inferido por nuestro agente de análisis a partir de la descripción oficial, el vector CVSS y la CWE, y comprobado por un supervisor. Puede contener errores.
🛡️ Mitigaciones ATT&CK que cubren estas técnicas
Tecnologías afectadas (1)
⚠ Inferidas por IA a partir de la descripción — NVD aún no ha analizado esta CVE; no son CPE verificados.
Referencias
JSON original (NVD)
Mostrar
{
"id": "CVE-2026-89815",
"cveTags": [],
"metrics": {
"cvssMetricV31": [
{
"type": "Secondary",
"source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"cvssData": {
"scope": "UNCHANGED",
"version": "3.1",
"baseScore": 7.8,
"attackVector": "LOCAL",
"baseSeverity": "HIGH",
"vectorString": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H",
"integrityImpact": "HIGH",
"userInteraction": "NONE",
"attackComplexity": "LOW",
"availabilityImpact": "HIGH",
"privilegesRequired": "LOW",
"confidentialityImpact": "HIGH"
},
"impactScore": 5.9,
"exploitabilityScore": 1.8
}
]
},
"affected": [
{
"source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"affectedData": [
{
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"product": "Linux",
"versions": [
{
"status": "affected",
"version": "b63d715b8090aed48bdef5930625946fa4c0d324",
"lessThan": "329ddc5d438f991f49e4fd24c704d1c7288d5e03",
"versionType": "git"
},
{
"status": "affected",
"version": "b63d715b8090aed48bdef5930625946fa4c0d324",
"lessThan": "a46ab76b6cf5478e2ac7b942a377c7a1827b436a",
"versionType": "git"
},
{
"status": "affected",
"version": "b63d715b8090aed48bdef5930625946fa4c0d324",
"lessThan": "941ac10529b3be5965a88d432a161ab459672ba8",
"versionType": "git"
}
],
"programFiles": [
"drivers/gpu/drm/ttm/ttm_pool.c"
],
"defaultStatus": "unaffected"
},
{
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"product": "Linux",
"versions": [
{
"status": "affected",
"version": "6.15"
},
{
"status": "unaffected",
"version": "0",
"lessThan": "6.15",
"versionType": "semver"
},
{
"status": "unaffected",
"version": "6.18.53",
"versionType": "semver",
"lessThanOrEqual": "6.18.*"
},
{
"status": "unaffected",
"version": "7.2.5",
"versionType": "semver",
"lessThanOrEqual": "7.2.*"
},
{
"status": "unaffected",
"version": "7.3-rc1",
"versionType": "original_commit_for_fix",
"lessThanOrEqual": "*"
}
],
"programFiles": [
"drivers/gpu/drm/ttm/ttm_pool.c"
],
"defaultStatus": "affected"
}
]
}
],
"published": "2026-09-16T11:16:46.720",
"references": [
{
"url": "https://git.kernel.org/stable/c/329ddc5d438f991f49e4fd24c704d1c7288d5e03",
"source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
},
{
"url": "https://git.kernel.org/stable/c/941ac10529b3be5965a88d432a161ab459672ba8",
"source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
},
{
"url": "https://git.kernel.org/stable/c/a46ab76b6cf5478e2ac7b942a377c7a1827b436a",
"source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
}
],
"vulnStatus": "Received",
"descriptions": [
{
"lang": "en",
"value": "In the Linux kernel, the following vulnerability has been resolved:\n\ndrm/ttm: Drop tt->restore after successful restore\n\nttm_pool_restore_and_alloc() can successfully complete the restore\nprocess via ttm_pool_restore_commit(), but tt->restore is not dropped\nafterward. As a result, subsequent backup/restore flows observe what\nappears to be a completed restore, while in reality shmem handles are\nstill installed in tt->pages, leading to the stack trace below.\n\nFix this by freeing and dropping tt->restore in\nttm_pool_restore_and_alloc() upon successful completion of the restore.\n\n20545 [ 309.784531] RIP: 0010:sg_alloc_append_table_from_pages+0x38c/0x490\n20547 [ 309.809570] RSP: 0018:ffffc9000623b838 EFLAGS: 00010206\n20548 [ 309.814827] RAX: 0000000000001000 RBX: ffff88816e42a160 RCX: 0000000000000000\n20549 [ 309.821986] RDX: 0000000000002000 RSI: 0000000000000003 RDI: 0000000000001000\n20550 [ 309.829147] RBP: ffff88816e42a168 R08: 0000000000000002 R09: 000000007ffff000\n20551 [ 309.836310] R10: ffffc9000623b928 R11: 0000000000000000 R12: 000000007ffff000\n20552 [ 309.843471] R13: ffff88815ba5a100 R14: 0000000000000000 R15: 0000000000000001\n20553 [ 309.850634] FS: 00007f9ff305e700(0000) GS:ffff888276c94000(0000) knlGS:0000000000000000\n20554 [ 309.858749] CS: 0010 DS: 0000 ES: 0000 CR0: 0000000080050033\n20555 [ 309.864519] CR2: 00007f9fca701000 CR3: 00000001565e2005 CR4: 0000000008f70ef0\n20556 [ 309.871678] PKRU: 55555558\n20557 [ 309.874403] Call Trace:\n20558 [ 309.876866] <TASK>\n20559 [ 309.878988] sg_alloc_table_from_pages_segment+0x60/0x100\n20560 [ 309.884415] ? ttm_resource_manager_usage+0x36/0x60 [ttm]\n20561 [ 309.889845] ? xe_tt_map_sg+0x7d/0xd0 [xe]\n20562 [ 309.894045] xe_tt_map_sg+0x7d/0xd0 [xe]\n20563 [ 309.898037] xe_bo_move+0x927/0xaa0 [xe]\n20564 [ 309.902029] ttm_bo_handle_move_mem+0xba/0x170 [ttm]\n20565 [ 309.907022] ttm_bo_validate+0xbe/0x190 [ttm]\n20566 [ 309.911405] xe_bo_validate+0x9a/0x120 [xe]\n20567 [ 309.915663] xe_gpuvm_validate+0xd9/0x140 [xe]\n20568 [ 309.920206] drm_gpuvm_validate+0x2f0/0x5b0 [drm_gpuvm]\n20569 [ 309.925459] ? drm_exec_lock_obj+0x63/0x210 [drm_exec]\n20570 [ 309.930627] xe_vm_validate_rebind+0x46/0xb0 [xe]\n20571 [ 309.935428] xe_exec_fn+0x20/0x40 [xe]\n20572 [ 309.939249] drm_gpuvm_exec_lock+0x78/0xc0 [drm_gpuvm]\n20573 [ 309.944410] xe_validation_exec_lock+0x5a/0xa0 [xe]\n20574 [ 309.949385] xe_exec_ioctl+0x806/0xc30 [xe]\n20575 [ 309.953639] ? ttwu_queue_wakelist+0xd9/0xf0\n20576 [ 309.957935] ? __pfx_xe_exec_fn+0x10/0x10 [xe]\n20577 [ 309.962449] ? __wake_up_common+0x73/0xa0\n20578 [ 309.966482] ? __pfx_xe_exec_ioctl+0x10/0x10 [xe]\n20579 [ 309.971263] drm_ioctl_kernel+0xa3/0x100\n20580 [ 309.975209] drm_ioctl+0x213/0x440\n20581 [ 309.978637] ? __pfx_xe_exec_ioctl+0x10/0x10 [xe]\n20582 [ 309.983415] xe_drm_ioctl+0x67/0xd0 [xe]\n20583 [ 309.987408] __x64_sys_ioctl+0x7f/0xd0"
}
],
"lastModified": "2026-09-21T14:17:27.127",
"sourceIdentifier": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
}