Home

Description

In the Linux kernel, the following vulnerability has been resolved: drm/xe: Fix oops in xe_gem_fault when running core_hotunplug test. I saw an oops in xe_gem_fault when running the xe-fast-feedback testlist against the realtime kernel without debug options enabled. The panic happens after core_hotunplug unbind-rebind finishes. Presumably what happens is that a process mmaps, unlocks because of the FAULT_FLAG_RETRY_NOWAIT logic, has no process memory left, causing ttm_bo_vm_dummy_page() to return VM_FAULT_NOPAGE, since there was nothing left to populate, and then oopses in "mem_type_is_vram(tbo->resource->mem_type)" because tbo->resource is NULL. It's convoluted, but fits the data and explains the oops after the test exits.

PUBLISHED Reserved 2025-04-16 | Published 2025-12-09 | Updated 2025-12-09 | Assigner Linux

Product status

Default status
unaffected

1da177e4c3f41524e886b7f1b8a0c1fc7321cac2 (git) before 99428bd6123d5676209dfb1d7a8f176cc830b665
affected

1da177e4c3f41524e886b7f1b8a0c1fc7321cac2 (git) before 29a3064f9c5a908aaf0b39cd6ed30374db11840d
affected

1da177e4c3f41524e886b7f1b8a0c1fc7321cac2 (git) before 1cda3c755bb7770be07d75949bb0f45fb88651f6
affected

Default status
affected

6.12.58 (semver)
unaffected

6.17.8 (semver)
unaffected

6.18 (original_commit_for_fix)
unaffected

References

git.kernel.org/...c/99428bd6123d5676209dfb1d7a8f176cc830b665

git.kernel.org/...c/29a3064f9c5a908aaf0b39cd6ed30374db11840d

git.kernel.org/...c/1cda3c755bb7770be07d75949bb0f45fb88651f6

cve.org (CVE-2025-40340)

nvd.nist.gov (CVE-2025-40340)

Download JSON