PT-2026-61201 · Linux · Linux
CVE-2026-63884
·
Published
2026-07-19
·
Updated
2026-07-19
CVSS v3.1
7.8
High
| Vector | AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H |
In the Linux kernel, the following vulnerability has been resolved:
drm/i915: Fix potential UAF in TTM object purge
TLDR: The bo->ttm object might be changed by calling ttm bo validate(),
move casting it to an i915 tt object later to actually get the right
pointer.
A user reported hitting the following bug under heavy use on DG2:
[26620.095550] Oops: general protection fault, probably for non-canonical address 0xa56b6b6b6b6b6b8b: 0000 1 SMP NOPTI
[26620.095556] CPU: 2 UID: 0 PID: 631 Comm: Xorg Not tainted 6.18.8 #1 PREEMPT(lazy)
[26620.095558] Hardware name: ASRock B850M Steel Legend WiFi/B850M Steel Legend WiFi, BIOS 3.50 09/18/2025
[26620.095559] RIP: 0010:i915 ttm purge+0x84/0x100 [i915]
[26620.095604] Code: 00 00 00 48 8d 54 24 10 48 89 e6 48 89 fb e8 83 aa ae ff 85 c0 75 6f 48 83 bb a8 01 00 00 00 74 2c 48 8b 45 78 48 85 c0 74 23 <48> 8b 78 20 48 c7 c2 ff ff ff ff 31 f6 e8 7a 73 e3 e0 48 8b 7d 78
[26620.095605] RSP: 0018:ffffc90005fd7430 EFLAGS: 00010282
[26620.095607] RAX: a56b6b6b6b6b6b6b RBX: ffff8881f46c3dc0 RCX: 0000000000000000
[26620.095608] RDX: 0000000000000000 RSI: 0000000000000246 RDI: 00000000ffffffff
[26620.095609] RBP: ffff888289610f00 R08: 0000000000000001 R09: ffff88823b022000
[26620.095609] R10: ffff888103029b28 R11: ffff8881fc7f3800 R12: ffff88810b6150d0
[26620.095609] R13: ffff888289610f00 R14: 0000000000000000 R15: ffff8881f46c3dc0
[26620.095610] FS: 00007f1004d86900(0000) GS:ffff88901c858000(0000) knlGS:0000000000000000
[26620.095611] CS: 0010 DS: 0000 ES: 0000 CR0: 0000000080050033
[26620.095611] CR2: 00007f0fdf489000 CR3: 000000035b0c1000 CR4: 0000000000750ef0
[26620.095612] PKRU: 55555554
[26620.095612] Call Trace:
[26620.095615]
[26620.095615] i915 ttm move+0x2b9/0x420 [i915]
[26620.095642] ? ttm tt init+0x65/0x80 [ttm]
[26620.095644] ? i915 ttm tt create+0xc6/0x150 [i915]
[26620.095667] ttm bo handle move mem+0xb6/0x160 [ttm]
[26620.095669] ttm bo evict+0x100/0x150 [ttm]
[26620.095671] ? preempt count add+0x64/0xa0
[26620.095673] ? raw spin lock+0xe/0x30
[26620.095675] ? raw spin unlock+0xd/0x30
[26620.095675] ? i915 gem object evictable+0xb7/0xd0 [i915]
[26620.095704] ttm bo evict cb+0x6e/0xd0 [ttm]
[26620.095705] ttm lru walk for evict+0xa6/0x200 [ttm]
[26620.095708] ttm bo alloc resource+0x185/0x4f0 [ttm]
[26620.095709] ? init object+0x62/0xd0
[26620.095712] ttm bo validate+0x7a/0x180 [ttm]
[26620.095713] ? raw spin unlock irqrestore+0x16/0x30
[26620.095714] i915 ttm get pages+0xb0/0x170 [i915]
[26620.095737] i915 ttm get pages+0x9f/0x150 [i915]
[26620.095759] ? i915 gem do execbuffer+0xedc/0x2b40 [i915]
[26620.095786] ? alloc debug processing+0xd0/0x100
[26620.095787] ? raw spin unlock irqrestore+0x16/0x30
[26620.095788] ? i915 vma instance+0xa0/0x4e0 [i915]
[26620.095822] i915 gem object get pages+0x2f/0x40 [i915]
[26620.095848] i915 vma pin ww+0x706/0x980 [i915]
[26620.095875] ? i915 gem do execbuffer+0xedc/0x2b40 [i915]
[26620.095904] eb validate vmas+0x170/0xa00 [i915]
[26620.095930] i915 gem do execbuffer+0x1201/0x2b40 [i915]
[26620.095953] ? alloc debug processing+0xd0/0x100
[26620.095954] ? raw spin unlock irqrestore+0x16/0x30
[26620.095955] ? i915 gem execbuffer2 ioctl+0xc9/0x240 [i915]
[26620.095977] ? wake up sync key+0x32/0x50
[26620.095979] ? i915 gem execbuffer2 ioctl+0xc9/0x240 [i915]
[26620.096001] ? slab alloc.isra.0+0x67/0xc0
[26620.096003] i915 gem execbuffer2 ioctl+0x11a/0x240 [i915]
Results from decode stacktrace.sh pointed to dereference of a file pointer
field of a i915 TTM page vector container associated with an object being
purged on eviction. That path is taken when the object is marked as no
longer needed.
Code analysis revealed a possibility of the i915 TTM page vector container
being replaced with a new instance inside a function that purges content
of the object, should it be still busy. That function is called,
indirectly via a more general function that changes the object's placement
and caching policy,
---truncated---
Fix
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Linux