From mboxrd@z Thu Jan 1 00:00:00 1970 Received: from smtp.kernel.org (aws-us-west-2-korg-mail-alma10-1.taild15c8.ts.net [100.103.45.18]) (using TLSv1.2 with cipher ECDHE-RSA-AES256-GCM-SHA384 (256/256 bits)) (No client certificate requested) by smtp.subspace.kernel.org (Postfix) with ESMTPS id 5BA2C58038D for ; Wed, 9 Sep 2026 16:13:27 +0000 (UTC) Authentication-Results: smtp.subspace.kernel.org; arc=none smtp.client-ip=100.103.45.18 ARC-Seal:i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1788970408; cv=none; b=Oft7ehFgNiqTjK9SWmptVR7awzof0BjocrzKA/Ytc69TBJjUuQzkLCVhol/AH8uhHeu16V4dPbgTmrWgEaJZp0O/eGmkan7hHAm2jSuAsV7VvNMf8Aa2tn9HFCmI60HltL+buHidCd9Tzp7YObeVqp4ahtwPLY6FjFzU7E2IPHY= ARC-Message-Signature:i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1788970408; c=relaxed/simple; bh=UpgTFCjyzm5CX+vqakywwNcb7JCWLm6F5FMZRSf92Js=; h=From:To:Cc:Subject:Date:Message-ID:MIME-Version; b=IaxJf+nSn/HmBSMc/FPFkccngn3DKD3ywddRsdFsyFiTaO+Z21EoULZgYVRNUBlkHwv3oZhDatawKx4C3QR6/tbH2r2iyxUp3t+JD6yRG3JMnbktVfGXolTgAkmDZRTKPLE0hR9rFlzygn20SjxdQoxLFLmedj4X6mWSIfNMFDg= ARC-Authentication-Results:i=1; smtp.subspace.kernel.org; dkim=pass (1024-bit key) header.d=linuxfoundation.org header.i=@linuxfoundation.org header.b=ozyoDH+S; arc=none smtp.client-ip=100.103.45.18 Authentication-Results: smtp.subspace.kernel.org; dkim=pass (1024-bit key) header.d=linuxfoundation.org header.i=@linuxfoundation.org header.b="ozyoDH+S" Received: by smtp.kernel.org (Postfix) with ESMTPSA id 906DA1F00A3A; Wed, 9 Sep 2026 16:13:26 +0000 (UTC) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=linuxfoundation.org; s=korg; t=1788970407; bh=4bmFY7bGiBzUN3KxwH0nT70p+dYPhRJxho/xbIVJKVU=; h=From:To:Cc:Subject:Date:Reply-To; b=ozyoDH+Sxi9SIGtK3QfKJ+3yNHaziub4t9tUJ2ceokXtjwwdWY/FEzlklUPG5ktAK hCcAyhB3SScUNhMo5kgULqgy1U5Zc763CNBQ/VcjO5YyCPgypwuCXvKd8nYoddCaHP j8dkXHBG1Joybu5VM6voDq6MNwBV6O3yHXWPNqTQ= From: Greg Kroah-Hartman To: linux-cve-announce@vger.kernel.org Cc: Greg Kroah-Hartman Subject: CVE-2026-80915: drm/xe: Fix DPT allocation paths. Date: Wed, 9 Sep 2026 18:13:15 +0200 Message-ID: <2026090914-CVE-2026-80915-0665@gregkh> X-Mailer: git-send-email 2.55.0 Reply-To: , Precedence: bulk X-Mailing-List: linux-cve-announce@vger.kernel.org List-Id: List-Subscribe: List-Unsubscribe: MIME-Version: 1.0 X-Developer-Signature: v=1; a=openpgp-sha256; l=2888; i=gregkh@linuxfoundation.org; h=from:subject:message-id; bh=R2BKXpkNR6xvXp+v9X0MaIr4GMn026jeMK9N6MBscnE=; b=owGbwMvMwCRo6H6F97bub03G02pJDFkLW2f9ePr408sqQ44e9jfXLEvcY3Rb12ytuFDFImq+r vD3VOu5HbEsDIJMDLJiiixftvEc3V9xSNHL0PY0zBxWJpAhDFycAjCRyfsZ5mf9XvS95l7M9aeL LiTO5PZr7+29lsCwoHuJr+Ks3ZHLum50fpzC8Pgy05oWDwA= X-Developer-Key: i=gregkh@linuxfoundation.org; a=openpgp; fpr=F4B60CC5BF78C2214A313DCB3147D40DDB2DFB29 Content-Transfer-Encoding: 8bit From: Greg Kroah-Hartman Description =========== In the Linux kernel, the following vulnerability has been resolved: drm/xe: Fix DPT allocation paths. Remove the fallback for VRAM to system memory, I tested it and that doesn't work at all, only a black screen with pipe fault errors were observed. On systems with media GT, extra latency is added when accessing stolen memory when the GT is in MC6. Since we additionally aren't counting how much memory is used for stolen and we could in theory fill up the entire stolen area with DPT's, avoid using stolen and only use the default memory region. Using stolen may also result in random system hangs under load. (cherry picked from commit a196406a3831291598fe8e73245914f7acffdfe0) The Linux kernel CVE team has assigned CVE-2026-80915 to this issue. Affected and fixed versions =========================== Issue introduced in 6.12 with commit 775d0adc01a55fe0458139330415d86bb3533efe and fixed in 6.12.106 with commit 491c499295fb0b90308b230b0a1075dcdf7f4d12 Issue introduced in 6.12 with commit 775d0adc01a55fe0458139330415d86bb3533efe and fixed in 6.18.47 with commit f03415030579163f791c978741af7f1f2f6510b7 Issue introduced in 6.12 with commit 775d0adc01a55fe0458139330415d86bb3533efe and fixed in 7.1.11 with commit c457e2c845ccbf2224386029f3da4937ba424db0 Issue introduced in 6.12 with commit 775d0adc01a55fe0458139330415d86bb3533efe and fixed in 7.2 with commit fc648757908304aedbad74f74bf58192aec383db Issue introduced in 6.11.3 with commit 4854ac2f88e2168ee4da2b152c6711772a8149aa Please see https://www.kernel.org for a full list of currently supported kernel versions by the kernel community. Unaffected versions might change over time as fixes are backported to older supported kernel versions. The official CVE entry at https://cve.org/CVERecord/?id=CVE-2026-80915 will be updated if fixes are backported, please check that for the most up to date information about this issue. Affected files ============== The file(s) affected by this issue are: drivers/gpu/drm/xe/display/xe_fb_pin.c Mitigation ========== The Linux kernel CVE team recommends that you update to the latest stable kernel version for this, and many other bugfixes. Individual changes are never tested alone, but rather are part of a larger kernel release. Cherry-picking individual commits is not recommended or supported by the Linux kernel community at all. If however, updating to the latest release is impossible, the individual changes to resolve this issue can be found at these commits: https://git.kernel.org/stable/c/491c499295fb0b90308b230b0a1075dcdf7f4d12 https://git.kernel.org/stable/c/f03415030579163f791c978741af7f1f2f6510b7 https://git.kernel.org/stable/c/c457e2c845ccbf2224386029f3da4937ba424db0 https://git.kernel.org/stable/c/fc648757908304aedbad74f74bf58192aec383db