« Volver al listado

CVE-2026-90409

Estado: RecibidaSin puntuar—

In the Linux kernel, the following vulnerability has been resolved:

drm/panthor: Add vm_bind region with kbo range overlap check

When a VM is created, caller has to specify the range of the address space carve-out set aside for mapping kernel BO's. That means vm_bind mappings of UM-exposed BO's should not intersect with that region, but at the moment we're not checking this.

At first, I thought of giving these values to drm_gpuvm_init() through its reserve_{offset, range} arguments, but it turns out that is meant for VM address spans that are not managed through the usual drm_gpuvm split/merge circuit, so storing the end of the user VA range at VM creation time and doing a quick check in the vm_bind ioctl path was the simplest workaround.

Leer descripción completaMostrar menos

The new check also makes sure vm_bind range doesn't overflow the size of a 64-bit unsigned integer. That was already being done further down the call stack inside drm_gpuvm_sm_map -> drm_gpuvm_range_valid, but it's best to fail early in the driver before GPUVM functions are invoked so that we won't waste time allocating vm_bind context resources.

CVSS

NVD no ha asignado puntuación CVSS a esta CVE (habitual desde el cambio de política de abril de 2026).

Probabilidad de explotación (EPSS)

EPSS (Exploit Prediction Scoring System, de FIRST) estima la probabilidad de que una vulnerabilidad sea explotada en 30 días. Complementa a CVSS (impacto) y a CISA KEV (explotación confirmada).

Tecnologías afectadas (1)

⚠ Inferidas por IA a partir de la descripción — NVD aún no ha analizado esta CVE; no son CPE verificados.

Referencias

JSON original (NVD)

Mostrar
{
  "id": "CVE-2026-90409",
  "cveTags": [],
  "metrics": {},
  "affected": [
    {
      "source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
      "affectedData": [
        {
          "repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
          "vendor": "Linux",
          "product": "Linux",
          "versions": [
            {
              "status": "affected",
              "version": "647810ec247641eb5aec8caef818919a4518a0b1",
              "lessThan": "761cf9c63274a5b711c3dc829601723215710d2d",
              "versionType": "git"
            },
            {
              "status": "affected",
              "version": "647810ec247641eb5aec8caef818919a4518a0b1",
              "lessThan": "985f5e12f3cdf43030e13c2bbd154913133b5c3f",
              "versionType": "git"
            }
          ],
          "programFiles": [
            "drivers/gpu/drm/panthor/panthor_mmu.c"
          ],
          "defaultStatus": "unaffected"
        },
        {
          "repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
          "vendor": "Linux",
          "product": "Linux",
          "versions": [
            {
              "status": "affected",
              "version": "6.10"
            },
            {
              "status": "unaffected",
              "version": "0",
              "lessThan": "6.10",
              "versionType": "semver"
            },
            {
              "status": "unaffected",
              "version": "7.2.6",
              "versionType": "semver",
              "lessThanOrEqual": "7.2.*"
            },
            {
              "status": "unaffected",
              "version": "7.3-rc1",
              "versionType": "original_commit_for_fix",
              "lessThanOrEqual": "*"
            }
          ],
          "programFiles": [
            "drivers/gpu/drm/panthor/panthor_mmu.c"
          ],
          "defaultStatus": "affected"
        }
      ]
    }
  ],
  "published": "2026-09-17T17:17:40.800",
  "references": [
    {
      "url": "https://git.kernel.org/stable/c/761cf9c63274a5b711c3dc829601723215710d2d",
      "source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
    },
    {
      "url": "https://git.kernel.org/stable/c/985f5e12f3cdf43030e13c2bbd154913133b5c3f",
      "source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
    }
  ],
  "vulnStatus": "Received",
  "descriptions": [
    {
      "lang": "en",
      "value": "In the Linux kernel, the following vulnerability has been resolved:\n\ndrm/panthor: Add vm_bind region with kbo range overlap check\n\nWhen a VM is created, caller has to specify the range of the address space\ncarve-out set aside for mapping kernel BO's. That means vm_bind mappings of\nUM-exposed BO's should not intersect with that region, but at the moment\nwe're not checking this.\n\nAt first, I thought of giving these values to drm_gpuvm_init() through its\nreserve_{offset, range} arguments, but it turns out that is meant for VM\naddress spans that are not managed through the usual drm_gpuvm split/merge\ncircuit, so storing the end of the user VA range at VM creation time and\ndoing a quick check in the vm_bind ioctl path was the simplest workaround.\n\nThe new check also makes sure vm_bind range doesn't overflow the size of a\n64-bit unsigned integer. That was already being done further down the call\nstack inside drm_gpuvm_sm_map -> drm_gpuvm_range_valid, but it's best to\nfail early in the driver before GPUVM functions are invoked so that we\nwon't waste time allocating vm_bind context resources."
    }
  ],
  "lastModified": "2026-09-17T17:17:40.800",
  "sourceIdentifier": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
}