CVE-2025-40166: drm/xe/guc: Check GuC running state before deregistering exec queue

Published Nov 12, 2025
·
Updated

In the Linux kernel, the following vulnerability has been resolved:

drm/xe/guc: Check GuC running state before deregistering exec queue

In normal operation, a registered exec queue is disabled and deregistered through the GuC, and freed only after the GuC confirms completion. However, if the driver is forced to unbind while the exec queue is still running, the user may call execdestroy() after the GuC has already been stopped and CT communication disabled.

In this case, the driver cannot receive a response from the GuC, preventing proper cleanup of exec queue resources. Fix this by directly releasing the resources when GuC is not running.

Here is the failure dmesg log: " [ 468.089581] ---[ end trace 0000000000000000 ]--- [ 468.089608] pci 0000:03:00.0: [drm] ERROR GT0: GUC ID manager unclean (1/65535) [ 468.090558] pci 0000:03:00.0: [drm] GT0: total 65535 [ 468.090562] pci 0000:03:00.0: [drm] GT0: used 1 [ 468.090564] pci 0000:03:00.0: [drm] GT0: range 1..1 (1) [ 468.092716] ------------[ cut here ]------------ [ 468.092719] WARNING: CPU: 14 PID: 4775 at drivers/gpu/drm/xe/xettmvrammgr.c:298 ttmvrammgrfini+0xf8/0x130 [xe] "

v2: use xeucfwisrunning() instead of xegucctenabled(). As CT may go down and come back during VF migration.

(cherry picked from commit 9b42321a02c50a12b2beb6ae9469606257fbecea)

Affected Software

1 affected component
Linux Linux kernel (drm/xe)

Event History

Nov 12, 2025
CVE Published
via MITRE·10:26 AM
Data Sourced
via MITRE·10:26 AM
DescriptionSeverity
Data Sourced
via NVD·11:15 AM
DescriptionSeverity
Free Weekly Intel

Don't miss critical vulnerabilities

Join thousands of security professionals who receive our weekly digest of trending CVEs, zero-days, and exploited vulnerabilities.

No spam. Unsubscribe anytime.

Frequently Asked Questions

1

What is the severity of CVE-2025-40166?

The severity of CVE-2025-40166 is categorized as medium, indicating potential risk but not an immediate threat.

2

How do I fix CVE-2025-40166?

To mitigate CVE-2025-40166, update to the latest version of the Linux kernel where the vulnerability has been resolved.

3

Which versions of the Linux kernel are affected by CVE-2025-40166?

CVE-2025-40166 affects specific versions of the Linux kernel, so users should consult the official release notes for details.

4

What are the potential impacts of CVE-2025-40166 on system security?

CVE-2025-40166 could allow unauthorized access or control over resources managed by the GuC, potentially compromising system integrity.

5

Is CVE-2025-40166 exploitable remotely?

CVE-2025-40166 is not considered remotely exploitable as it requires local access to the affected system.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203