« Volver al listado

CVE-2026-97620

Estado: RecibidaSin puntuar—

In the Linux kernel, the following vulnerability has been resolved:

drm/xe: Flush LSC untyped L1 dataport cache after rcs/ccs batches

emit_render_cache_flush() sets PIPE_CONTROL0_HDC_PIPELINE_FLUSH to flush the L2/HDC data cache before fence signalling, but it never requests a flush of the LSC untyped L1 data cache via the 'Untyped Data-Port Cache Flush Enable' bit in PIPE_CONTROL DWord0[11].

Per the Bspec, in 3D pipeline mode HDC Pipeline Flush is documented to also flush/invalidate the untyped L1 cache, but only depending on how HDC_CHICKEN0[13:11] is programmed.

Leer descripción completaMostrar menos

Starting with MTL, this coupling between HDC Pipeline Flush and the untyped L1 cache flush no longer holds in practice, regardless of how HDC_CHICKEN0 is programmed, so relying on it is not safe on newer platforms such as BMG. Mesa's Vulkan driver (anv) has been assuming the kernel flushes both caches between submissions, and hit user-visible corruption in apps such as Llama.cpp because of this gap; it now works around it by flushing both caches again from userspace at the end of every command buffer.

Correctness between submissions on the same queue is userspace's responsibility and belongs in Mesa, not the kernel. However, for security we must ensure stale data can't leak through the untyped L1 dataport cache once memory is reclaimed or evicted, which requires the KMD to flush it before releasing memory for reuse.

Prior to MTL, HDC_CHICKEN0 could be programmed (as already done for DG2 via Wa_22010960976/Wa_14013347512) to reliably keep HDC Pipeline Flush coupled to the untyped L1 cache flush, so those platforms are unaffected. Mesa's own anv driver found that on MTL the HW disconnected the two independently of how HDC_CHICKEN0 is programmed, and could not bring the old behavior back even by writing the register by hand; see Mesa commit 7c2ff46a4fc3 ("anv: don't prevent L1 untyped cache flush in 3D mode"). The kernel can't reliably request the flush from the CS on MTL either, so restrict the new PIPE_CONTROL bit to GRAPHICS_VERx100 >= 2000 (Xe2 and later), where it can be relied on.

Explicitly set PIPE_CONTROL0_UNTYPED_DATAPORT_CACHE_FLUSH together with PIPE_CONTROL0_HDC_PIPELINE_FLUSH in emit_render_cache_flush() on Xe2 and later, so the L1 data cache is known clean before memory is released for reuse, without depending on undocumented platform-specific HDC_CHICKEN0 behavior.

Bspec: 56551 (cherry picked from commit 434514b6fe731e873808297c268fc52cdf4a1ce6)

CVSS

NVD no ha asignado puntuación CVSS a esta CVE (habitual desde el cambio de política de abril de 2026).

Probabilidad de explotación (EPSS)

EPSS (Exploit Prediction Scoring System, de FIRST) estima la probabilidad de que una vulnerabilidad sea explotada en 30 días. Complementa a CVSS (impacto) y a CISA KEV (explotación confirmada).

Tecnologías afectadas (1)

⚠ Inferidas por IA a partir de la descripción — NVD aún no ha analizado esta CVE; no son CPE verificados.

Referencias

JSON original (NVD)

Mostrar
{
  "id": "CVE-2026-97620",
  "cveTags": [],
  "metrics": {},
  "affected": [
    {
      "source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
      "affectedData": [
        {
          "repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
          "vendor": "Linux",
          "product": "Linux",
          "versions": [
            {
              "status": "affected",
              "version": "9f8f93bee3efdba3bf7853befe2219e3a300c305",
              "lessThan": "d73975c121f56fe3fcbbfcfe3ea8853b9f597ab3",
              "versionType": "git"
            },
            {
              "status": "affected",
              "version": "9f8f93bee3efdba3bf7853befe2219e3a300c305",
              "lessThan": "fab569a69c3ae9beced68307e36048efa2709bec",
              "versionType": "git"
            },
            {
              "status": "affected",
              "version": "9f8f93bee3efdba3bf7853befe2219e3a300c305",
              "lessThan": "92393fc5227b2b701f2b1530c9cd6dac6ee90b71",
              "versionType": "git"
            },
            {
              "status": "affected",
              "version": "9f8f93bee3efdba3bf7853befe2219e3a300c305",
              "lessThan": "f5fcf7e638b904397ec0f66d3ea6766ef0cfe25b",
              "versionType": "git"
            }
          ],
          "programFiles": [
            "drivers/gpu/drm/xe/instructions/xe_gpu_commands.h",
            "drivers/gpu/drm/xe/xe_ring_ops.c"
          ],
          "defaultStatus": "unaffected"
        },
        {
          "repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
          "vendor": "Linux",
          "product": "Linux",
          "versions": [
            {
              "status": "affected",
              "version": "6.8"
            },
            {
              "status": "unaffected",
              "version": "0",
              "lessThan": "6.8",
              "versionType": "semver"
            },
            {
              "status": "unaffected",
              "version": "6.12.112",
              "versionType": "semver",
              "lessThanOrEqual": "6.12.*"
            },
            {
              "status": "unaffected",
              "version": "6.18.53",
              "versionType": "semver",
              "lessThanOrEqual": "6.18.*"
            },
            {
              "status": "unaffected",
              "version": "7.2.7",
              "versionType": "semver",
              "lessThanOrEqual": "7.2.*"
            },
            {
              "status": "unaffected",
              "version": "7.3-rc3",
              "versionType": "original_commit_for_fix",
              "lessThanOrEqual": "*"
            }
          ],
          "programFiles": [
            "drivers/gpu/drm/xe/instructions/xe_gpu_commands.h",
            "drivers/gpu/drm/xe/xe_ring_ops.c"
          ],
          "defaultStatus": "affected"
        }
      ]
    }
  ],
  "published": "2026-09-25T11:17:16.240",
  "references": [
    {
      "url": "https://git.kernel.org/stable/c/92393fc5227b2b701f2b1530c9cd6dac6ee90b71",
      "source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
    },
    {
      "url": "https://git.kernel.org/stable/c/d73975c121f56fe3fcbbfcfe3ea8853b9f597ab3",
      "source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
    },
    {
      "url": "https://git.kernel.org/stable/c/f5fcf7e638b904397ec0f66d3ea6766ef0cfe25b",
      "source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
    },
    {
      "url": "https://git.kernel.org/stable/c/fab569a69c3ae9beced68307e36048efa2709bec",
      "source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
    }
  ],
  "vulnStatus": "Received",
  "descriptions": [
    {
      "lang": "en",
      "value": "In the Linux kernel, the following vulnerability has been resolved:\n\ndrm/xe: Flush LSC untyped L1 dataport cache after rcs/ccs batches\n\nemit_render_cache_flush() sets PIPE_CONTROL0_HDC_PIPELINE_FLUSH to\nflush the L2/HDC data cache before fence signalling, but it never\nrequests a flush of the LSC untyped L1 data cache via the 'Untyped\nData-Port Cache Flush Enable' bit in PIPE_CONTROL DWord0[11].\n\nPer the Bspec, in 3D pipeline mode HDC Pipeline Flush is documented to\nalso flush/invalidate the untyped L1 cache, but only depending on how\nHDC_CHICKEN0[13:11] is programmed. Starting with MTL, this coupling\nbetween HDC Pipeline Flush and the untyped L1 cache flush no longer\nholds in practice, regardless of how HDC_CHICKEN0 is programmed, so\nrelying on it is not safe on newer platforms such as BMG. Mesa's Vulkan\ndriver (anv) has been assuming the kernel flushes both caches between\nsubmissions, and hit user-visible corruption in apps such as Llama.cpp\nbecause of this gap; it now works around it by flushing both caches\nagain from userspace at the end of every command buffer.\n\nCorrectness between submissions on the same queue is userspace's\nresponsibility and belongs in Mesa, not the kernel. However, for\nsecurity we must ensure stale data can't leak through the untyped L1\ndataport cache once memory is reclaimed or evicted, which requires the\nKMD to flush it before releasing memory for reuse.\n\nPrior to MTL, HDC_CHICKEN0 could be programmed (as already done for\nDG2 via Wa_22010960976/Wa_14013347512) to reliably keep HDC Pipeline\nFlush coupled to the untyped L1 cache flush, so those platforms are\nunaffected. Mesa's own anv driver found that on MTL the HW\ndisconnected the two independently of how HDC_CHICKEN0 is programmed,\nand could not bring the old behavior back even by writing the register\nby hand; see Mesa commit 7c2ff46a4fc3 (\"anv: don't prevent L1 untyped\ncache flush in 3D mode\"). The kernel can't reliably request the flush\nfrom the CS on MTL either, so restrict the new PIPE_CONTROL bit to\nGRAPHICS_VERx100 >= 2000 (Xe2 and later), where it can be relied on.\n\nExplicitly set PIPE_CONTROL0_UNTYPED_DATAPORT_CACHE_FLUSH together\nwith PIPE_CONTROL0_HDC_PIPELINE_FLUSH in emit_render_cache_flush() on\nXe2 and later, so the L1 data cache is known clean before memory is\nreleased for reuse, without depending on undocumented\nplatform-specific HDC_CHICKEN0 behavior.\n\nBspec: 56551\n(cherry picked from commit 434514b6fe731e873808297c268fc52cdf4a1ce6)"
    }
  ],
  "lastModified": "2026-10-03T11:18:08.257",
  "sourceIdentifier": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
}