{"dataType":"CVE_RECORD","dataVersion":"5.2","cveMetadata":{"cveId":"CVE-2026-63863","assignerOrgId":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","state":"PUBLISHED","assignerShortName":"Linux","dateReserved":"2026-07-19T07:54:57.017Z","datePublished":"2026-07-19T14:04:49.967Z","dateUpdated":"2026-08-05T12:36:39.194Z"},"containers":{"cna":{"providerMetadata":{"orgId":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","shortName":"Linux","dateUpdated":"2026-08-05T12:36:39.194Z"},"descriptions":[{"lang":"en","value":"In the Linux kernel, the following vulnerability has been resolved:\n\ndrm/gpusvm: Fix unbalanced unlock in drm_gpusvm_scan_mm()\n\nThere is a unbalanced lock/unlock to gpusvm notifier lock:\n[  931.045868] =====================================\n[  931.046509] WARNING: bad unlock balance detected!\n[  931.047149] 6.19.0-rc6+xe-**************** #9 Tainted: G     U\n[  931.048150] -------------------------------------\n[  931.048790] kworker/u5:0/51 is trying to release lock (&gpusvm->notifier_lock) at:\n[  931.049801] [<ffffffffa090c0d8>] drm_gpusvm_scan_mm+0x188/0x460 [drm_gpusvm_helper]\n[  931.050802] but there are no more locks to release!\n[  931.051463]\n\nThe drm_gpusvm_notifier_unlock() sits under err_free label and the\nfirst jump to err_free is just before calling the\ndrm_gpusvm_notifier_lock() causing unbalanced unlock."}],"metrics":[{"cvssV3_1":{"version":"3.1","vectorString":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H","baseScore":8.8,"baseSeverity":"HIGH"},"scenarios":[{"lang":"en","value":"AV:L - The vulnerable code is only reached via Intel Xe DRM ioctls (DRM_XE_VM_BIND prefetch, GPU page-fault handling) on /dev/dri/renderD*, which require local access to the GPU device node.\nAC:L - An attacker can reliably trigger the bug by racing CPU memory operations (munmap/mremap/mprotect) against GPU SVM VRAM migration to force hmm_range_fault() to return an error or time out on -EBUSY, hitting the err_free path without holding notifier_lock.\nPR:L - Exploitation requires opening the DRM render node (DRM_RENDER_ALLOW), which is available to unprivileged users in the render group on typical desktop and cloud GPU instances, not root or capabilities.\nUI:N - No victim interaction is required; the attacker triggers the condition through their own GPU VM bindings, compute submissions, and concurrent memory manipulation.\nS:C - Corrupting notifier_lock breaks the documented IOMMU security model for GPU SVM, allowing GPU DMA operations to proceed without proper invalidation synchronization and potentially accessing host memory outside the attacker's GPU context.\nC:H - Rwsem corruption from the spurious unlock can desynchronize invalidation from migration, enabling races where the GPU reads stale or freed pages that may have been reallocated, constituting arbitrary memory disclosure.\nI:H - The same lock corruption can allow GPU DMA writes to pages during or after invalidation races, providing a path to arbitrary memory corruption and potential privilege escalation.\nA:H - The bug triggers a kernel lockdep warning (\"bad unlock balance detected\") and rwsem corruption can cause kernel oops, hangs, or panic during subsequent notifier_lock operations."}]}],"affected":[{"product":"Linux","vendor":"Linux","defaultStatus":"unaffected","repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","programFiles":["drivers/gpu/drm/drm_gpusvm.c"],"versions":[{"version":"f1d08a5864822684773105c60528e2abb577ca6c","lessThan":"8efaa47a871662a8c21b819cec60786f7ef17ab4","status":"affected","versionType":"git"},{"version":"f1d08a5864822684773105c60528e2abb577ca6c","lessThan":"d287dee565c3c32e1ed76ec1847af46809c29b90","status":"affected","versionType":"git"}]},{"product":"Linux","vendor":"Linux","defaultStatus":"affected","repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","programFiles":["drivers/gpu/drm/drm_gpusvm.c"],"versions":[{"version":"7.0","status":"affected"},{"version":"0","lessThan":"7.0","status":"unaffected","versionType":"semver"},{"version":"7.0.10","lessThanOrEqual":"7.0.*","status":"unaffected","versionType":"semver"},{"version":"7.1","lessThanOrEqual":"*","status":"unaffected","versionType":"original_commit_for_fix"}]}],"cpeApplicability":[{"nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*","versionStartIncluding":"7.0","versionEndExcluding":"7.0.10"},{"vulnerable":true,"criteria":"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*","versionStartIncluding":"7.0","versionEndExcluding":"7.1"}]}]}],"references":[{"url":"https://git.kernel.org/stable/c/8efaa47a871662a8c21b819cec60786f7ef17ab4"},{"url":"https://git.kernel.org/stable/c/d287dee565c3c32e1ed76ec1847af46809c29b90"}],"title":"drm/gpusvm: Fix unbalanced unlock in drm_gpusvm_scan_mm()","x_generator":{"engine":"bippy-1.2.0"}}}}