{"dataType":"CVE_RECORD","dataVersion":"5.2","cveMetadata":{"cveId":"CVE-2026-93284","assignerOrgId":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","state":"PUBLISHED","assignerShortName":"Linux","dateReserved":"2026-09-17T16:02:15.099Z","datePublished":"2026-09-24T16:02:08.527Z","dateUpdated":"2026-10-03T10:57:10.141Z"},"containers":{"cna":{"providerMetadata":{"orgId":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","shortName":"Linux","dateUpdated":"2026-10-03T10:57:10.141Z"},"descriptions":[{"lang":"en","value":"In the Linux kernel, the following vulnerability has been resolved:\n\ndrm/pagemap: dma-unmap pages before handling migration errors\n\ndrm_pagemap_migrate_unmap_pages() relies on the pages array to determine\nwhich pages require DMA unmapping. However,\ndrm_pagemap_migration_unlock_put_pages() clears the array as part of its\ncleanup, leaving drm_pagemap_migrate_unmap_pages() with no valid page\ninformation if it is called afterward.\n\nCall drm_pagemap_migrate_unmap_pages() before\ndrm_pagemap_migration_unlock_put_pages() so the pages array remains\nvalid during DMA unmapping."}],"metrics":[{"cvssV3_1":{"version":"3.1","vectorString":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H","baseScore":8.8,"baseSeverity":"HIGH"},"scenarios":[{"lang":"en","value":"AV:L - Local ioctl/fault path only: DRM_IOCTL_XE_VM_CREATE (FAULT_MODE) and DRM_IOCTL_XE_VM_BIND (CPU_ADDR_MIRROR) on /dev/dri/renderD* migrate the caller's anonymous range to VRAM, then do_swap_page() invokes drm_pagemap_migrate_to_ram() -> __drm_pagemap_migrate_to_ram(), or xe_bo_move() calls xe_svm_bo_evict() -> drm_pagemap_evict_to_ram(). No remote protocol byte reaches those functions.\nAC:L - The attacker creates the SVM range, migrates it to VRAM, and CPU-faults or TTM-evicts it. After drm_pagemap_migrate_map_system_pages() has dma_map_page()'d dest folios, they force err_finalize by exhausting gt->usm.bb_pool so xe_svm_copy_to_ram()/xe_bb_new() returns -ENOMEM, or by fragmenting IOVA so dma_iova_try_alloc() fails and a later dma_map_page() returns -EFAULT. No victim timing.\nPR:L - DRM_IOCTL_XE_VM_CREATE and DRM_IOCTL_XE_VM_BIND are DRM_RENDER_ALLOW; xe_vm_create_ioctl() performs no capable() or DRM-master check. An unprivileged local user with typical render/video-group access to /dev/dri/renderD* on an Intel Xe discrete GPU (CONFIG_DRM_XE_PAGEMAP defaults to y) can create a fault-mode VM and reach the patched functions.\nUI:N - The attacking process opens the render node, creates its own fault-mode VM, CPU_ADDR_MIRROR-binds its anonymous mapping, prefetches or GPU-faults it into VRAM, then CPU-accesses or forces TTM eviction. No other user must mount a filesystem or open a file.\nS:C - On err_finalize, drm_pagemap_migration_unlock_put_pages() folio_put()s the destination RAM folios and zeros migrate_pfn, so drm_pagemap_migrate_unmap_pages() sees a NULL page and skips dma_unmap_page(). Those IOMMU PTEs remain aimed at pages already returned to the buddy allocator, which is an IOMMU/DMA isolation bypass.\nC:H - Destination folios from drm_pagemap_migrate_populate_ram_pfn() are put while still dma_map_page()'d. Recycled host pages stay IOMMU-reachable through the leaked translation, so later DMA can disclose their new kernel or cross-process contents rather than a bounded pointer leak.\nI:H - The leaked mappings are DMA_FROM_DEVICE (Xe copy-from-VRAM via xe_svm_copy_to_ram()). After folio_put(), a GPU/IOMMU transaction through those IOVAs writes into whatever reused the physical pages, an arbitrary physical write through the IOMMU rather than a bounded corruption.\nA:H - Each failed __drm_pagemap_migrate_to_ram()/drm_pagemap_evict_to_ram() leaks that range's dma_map_page() IOVAs; the attacker loops CPU faults after inducing xe_bb_new() or map errors. Unbounded IOVA growth wedges later maps, and DMA into buddy-reused pages oopses or panics, not a mere slowdown."}]}],"affected":[{"product":"Linux","vendor":"Linux","defaultStatus":"unaffected","repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","programFiles":["drivers/gpu/drm/drm_pagemap.c"],"versions":[{"version":"f86ad0ed620cb3c91ec7d5468e93ac68d727539d","lessThan":"e4331c6644db85bc6ceb470bd84bcf371b6dbfa6","status":"affected","versionType":"git"},{"version":"f86ad0ed620cb3c91ec7d5468e93ac68d727539d","lessThan":"415f5a755cec5164b149037bf294e270b78d36c6","status":"affected","versionType":"git"},{"version":"f86ad0ed620cb3c91ec7d5468e93ac68d727539d","lessThan":"9e6372ec2a3990662ae0a67f56ac0aee19848d5b","status":"affected","versionType":"git"}]},{"product":"Linux","vendor":"Linux","defaultStatus":"affected","repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","programFiles":["drivers/gpu/drm/drm_pagemap.c"],"versions":[{"version":"6.17","status":"affected"},{"version":"0","lessThan":"6.17","status":"unaffected","versionType":"semver"},{"version":"6.18.53","lessThanOrEqual":"6.18.*","status":"unaffected","versionType":"semver"},{"version":"7.2.9","lessThanOrEqual":"7.2.*","status":"unaffected","versionType":"semver"},{"version":"7.3-rc2","lessThanOrEqual":"*","status":"unaffected","versionType":"original_commit_for_fix"}]}],"cpeApplicability":[{"nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*","versionStartIncluding":"6.17","versionEndExcluding":"6.18.53"},{"vulnerable":true,"criteria":"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*","versionStartIncluding":"6.17","versionEndExcluding":"7.2.9"},{"vulnerable":true,"criteria":"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*","versionStartIncluding":"6.17","versionEndExcluding":"7.3-rc2"}]}]}],"references":[{"url":"https://git.kernel.org/stable/c/e4331c6644db85bc6ceb470bd84bcf371b6dbfa6"},{"url":"https://git.kernel.org/stable/c/415f5a755cec5164b149037bf294e270b78d36c6"},{"url":"https://git.kernel.org/stable/c/9e6372ec2a3990662ae0a67f56ac0aee19848d5b"}],"title":"drm/pagemap: dma-unmap pages before handling migration errors","x_generator":{"engine":"bippy-1.2.0"}}}}