From mboxrd@z Thu Jan 1 00:00:00 1970 Received: from smtp.kernel.org (aws-us-west-2-korg-mail-alma10-1.taild15c8.ts.net [100.103.45.18]) (using TLSv1.2 with cipher ECDHE-RSA-AES256-GCM-SHA384 (256/256 bits)) (No client certificate requested) by smtp.subspace.kernel.org (Postfix) with ESMTPS id 8067E3C585C for ; Mon, 10 Aug 2026 12:03:24 +0000 (UTC) Authentication-Results: smtp.subspace.kernel.org; arc=none smtp.client-ip=100.103.45.18 ARC-Seal:i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1786363405; cv=none; b=cmmeQ86h/y4gAA6FuMeUONNKd7xX6w9++ScHa94Fvr4YdtRFwYDLme9JTM8bI3n8k1TFDsdUX3lK4OGPXa/ZavowZI9WgpXDg4Fpo/DQN9CgE7uQhDoF12gd6bL4KZy49E3NMNgSuaXZeW1SHROQf6FsT2m5m6egQLWDzdA7zKs= ARC-Message-Signature:i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1786363405; c=relaxed/simple; bh=CINg2QDj+YUpbqTcfGPaXOIAXMOmZ8opprmK2KUyWWA=; h=From:To:Cc:Subject:Date:Message-ID:MIME-Version; b=kfZs9ZJfoo4UplZ37xXczt3VeTmDRyu2U4vmZ7lcS/LpE9cjW5PQTn1Ni7MR3TEmb76ERBFn+phYB4uECShTCkRELj60Rvd70Tocmj9pQs9EyasaiaAuOgWEbV/tSJLQPx0BptOJW+aqEq/xSFwjSPOdYt2+oXRT5ISk2JaJSHY= ARC-Authentication-Results:i=1; smtp.subspace.kernel.org; dkim=pass (1024-bit key) header.d=linuxfoundation.org header.i=@linuxfoundation.org header.b=N2ihbzzO; arc=none smtp.client-ip=100.103.45.18 Authentication-Results: smtp.subspace.kernel.org; dkim=pass (1024-bit key) header.d=linuxfoundation.org header.i=@linuxfoundation.org header.b="N2ihbzzO" Received: by smtp.kernel.org (Postfix) with ESMTPSA id 064311F000E9; Mon, 10 Aug 2026 12:03:23 +0000 (UTC) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=linuxfoundation.org; s=korg; t=1786363404; bh=jk+yS34sJGCxIaDuKHBDEhsNcZafFWySoeCgdmRpmQ8=; h=From:To:Cc:Subject:Date:Reply-To; b=N2ihbzzOauJ+7HwVr/iMDg74+qPfU7o7mxpnP/Ts147Jn9rSldupBhwVwWUV7X8WP e+Dv6HaNxxByed2W+TzeYzX37OOVQiVPVIE5duOc7w2phxgdXIkLhMh8I+3Np8wBY/ p7t86vJlwBPMlwToybXyTicEYGEyBa5DNOj8v03A= From: Greg Kroah-Hartman To: linux-cve-announce@vger.kernel.org Cc: Greg Kroah-Hartman Subject: CVE-2026-68102: drm/amdgpu: fix aperture mapping leak Date: Mon, 10 Aug 2026 13:56:59 +0200 Message-ID: <2026081052-CVE-2026-68102-9061@gregkh> X-Mailer: git-send-email 2.55.0 Reply-To: , Precedence: bulk X-Mailing-List: linux-cve-announce@vger.kernel.org List-Id: List-Subscribe: List-Unsubscribe: MIME-Version: 1.0 X-Developer-Signature: v=1; a=openpgp-sha256; l=3794; i=gregkh@linuxfoundation.org; h=from:subject:message-id; bh=BdWAFRM7DLg6DAMmbKRlYVcTf2EBMiRyiOz6nGgd9l8=; b=kA0DAAIRMUfUDdst+ykByyZiAGp5vISjjzeh9gIOmHE2KcDNlNj029mhtqOg282rQ8dxHq+Lr 4hdBAARAgAdFiEE9LYMxb94wiFKMT3LMUfUDdst+ykFAmp5vIQACgkQMUfUDdst+ynIfACfXzi4 jtvVtI0HVjSE3gjt9ltSwb8AoLWF7puFNn5ZVX51XQgbWCZgFVuf X-Developer-Key: i=gregkh@linuxfoundation.org; a=openpgp; fpr=F4B60CC5BF78C2214A313DCB3147D40DDB2DFB29 Content-Transfer-Encoding: 8bit From: Greg Kroah-Hartman Description =========== In the Linux kernel, the following vulnerability has been resolved: drm/amdgpu: fix aperture mapping leak amdgpu_pci_remove() calls drm_dev_unplug() before invoking the driver fini routines. This causes drm_dev_enter() in amdgpu_ttm_fini() to always return false, so iounmap(aper_base_kaddr) never runs on normal driver unload, leaving an orphaned entry in the x86 PAT interval tree. On connected_to_cpu hardware, the aperture is mapped write-back (WB) via ioremap_cache(). On reload, IP discovery calls memremap(..., MEMREMAP_WC) over the same range. The WC vs WB conflict causes: ioremap error for 0x..., requested 0x1, got 0x0 amdgpu: discovery failed: -2 Fix by switching to devres-managed mappings so cleanup is guaranteed regardless of drm_dev_enter() state: - connected_to_cpu path: devm_memremap(MEMREMAP_WB). For IORESOURCE_SYSTEM_RAM ranges this takes the try_ram_remap() shortcut, returning __va(offset) from the existing kernel direct map. No new ioremap VA or PAT entry is created, so there is nothing to orphan. - dGPU path: devm_ioremap_wc() registers iounmap() as a devres action, guaranteeing cleanup at device_del() time. Also remove iounmap(aper_base_kaddr) from amdgpu_device_unmap_mmio() since the mapping is now devres-owned. v2: Remove redundant x86_64 guard (Lijo) (cherry picked from commit d871e99879cb5fd1fa798b006b4888887e63a17a) The Linux kernel CVE team has assigned CVE-2026-68102 to this issue. Affected and fixed versions =========================== Issue introduced in 5.13 with commit 9d0af8b4def0de6b734ec8db08e96da0458facb6 and fixed in 6.6.148 with commit 67bc3647e418e23dc0d17604bdba634a73de809f Issue introduced in 5.13 with commit 9d0af8b4def0de6b734ec8db08e96da0458facb6 and fixed in 6.12.101 with commit a343d028ad6c174da8dc6af560c51e6d140a6727 Issue introduced in 5.13 with commit 9d0af8b4def0de6b734ec8db08e96da0458facb6 and fixed in 6.18.42 with commit 6405c4e75b3bcf0e72bd7a0ff5f1ed0c475e23aa Issue introduced in 5.13 with commit 9d0af8b4def0de6b734ec8db08e96da0458facb6 and fixed in 7.1.6 with commit f5988b5c300a32ff751724ffd33d5a8d5873e4a7 Issue introduced in 5.13 with commit 9d0af8b4def0de6b734ec8db08e96da0458facb6 and fixed in 7.2-rc2 with commit ea772a440d56b285f4d491affac50ecd41f6b402 Please see https://www.kernel.org for a full list of currently supported kernel versions by the kernel community. Unaffected versions might change over time as fixes are backported to older supported kernel versions. The official CVE entry at https://cve.org/CVERecord/?id=CVE-2026-68102 will be updated if fixes are backported, please check that for the most up to date information about this issue. Affected files ============== The file(s) affected by this issue are: drivers/gpu/drm/amd/amdgpu/amdgpu_device.c drivers/gpu/drm/amd/amdgpu/amdgpu_ttm.c Mitigation ========== The Linux kernel CVE team recommends that you update to the latest stable kernel version for this, and many other bugfixes. Individual changes are never tested alone, but rather are part of a larger kernel release. Cherry-picking individual commits is not recommended or supported by the Linux kernel community at all. If however, updating to the latest release is impossible, the individual changes to resolve this issue can be found at these commits: https://git.kernel.org/stable/c/67bc3647e418e23dc0d17604bdba634a73de809f https://git.kernel.org/stable/c/a343d028ad6c174da8dc6af560c51e6d140a6727 https://git.kernel.org/stable/c/6405c4e75b3bcf0e72bd7a0ff5f1ed0c475e23aa https://git.kernel.org/stable/c/f5988b5c300a32ff751724ffd33d5a8d5873e4a7 https://git.kernel.org/stable/c/ea772a440d56b285f4d491affac50ecd41f6b402