CVE-2026-46309: drm/xe/uapi: Reject coh_none PAT index for CPU cached memory in madvise

Published Jun 8, 2026
·
Updated

In the Linux kernel, the following vulnerability has been resolved:

drm/xe/uapi: Reject cohnone PAT index for CPU cached memory in madvise

Add validation in xevmmadviseioctl() to reject PAT indices with XECOHNONE coherency mode when applied to CPU cached memory.

Using cohnone with CPU cached buffers is a security issue. When the kernel clears pages before reallocation, the clear operation stays in CPU cache (dirty). GPU with cohnone can bypass CPU caches and read stale sensitive data directly from DRAM, potentially leaking data from previously freed pages of other processes.

This aligns with the existing validation in vmbind path (xevmbindioctlvalidatebo).

v2(Matthew brost) - Add fixes - Move one debug print to better place

v3(Matthew Auld) - Should be drm/xe/uapi - More Cc

v4(Shuicheng Lin) - Fix kmem leak issues by the way

v5 - Remove kmem leak because it has been merged by another patch

v6 - Remove the fix which is not related to current fix

v7 - No change

v8 - Rebase

v9 - Limit the restrictions to iGPU

v10 - No change

(cherry picked from commit 016ccdb674b8c899940b3944952c96a6a490d10a)

Affected Software

4 affected components
Linux Kernel Linux kernel
Linux Linux kernel>=6.18<6.18.32
Linux Linux kernel>=6.19<7.0.9
Linux Linux kernel=7.1-rc1

Remediation

Recommended actions to resolve this vulnerability, in priority order.

  1. Configuration

    In xe_vm_madvise_ioctl(), add validation to reject PAT indices with CPU cache (dirty) for XE_COH_NONE. This prevents using XE_COH_NONE coherency mode with CPU cached (dirty) buffers, aligning with existing validation in the vm_bind path and addressing the security issue.

    Linux kernel drm/xe/uapi madvise ioctl PAT index validation for XE_COH_NONE with CPU cached (dirty) memory = Reject PAT indices with CPU cache (dirty) when using XE_COH_NONE coherency mode

Event History

Jun 8, 2026
CVE Published
via MITRE·03:50 PM
Data Sourced
via MITRE·03:50 PM
Description
Data Sourced
via Red Hat·05:03 PM
DescriptionSeverityAffected Software
Data Sourced
via NVD·05:16 PM
RemedyDescriptionSeverityWeaknessAffected Software
Free Weekly Intel

Don't miss critical vulnerabilities

Join thousands of security professionals who receive our weekly digest of trending CVEs, zero-days, and exploited vulnerabilities.

No spam. Unsubscribe anytime.

Frequently Asked Questions

1

What is the severity of CVE-2026-46309?

CVE-2026-46309 has a risk score of 47, indicating a moderate severity level.

2

How do I fix CVE-2026-46309?

To fix CVE-2026-46309, ensure that your Linux kernel is updated to the latest version where this vulnerability has been patched.

3

What impact does CVE-2026-46309 have on Linux systems?

CVE-2026-46309 could potentially allow improper coherency handling for CPU cached memory, leading to stability issues.

4

Which versions of the Linux kernel are affected by CVE-2026-46309?

CVE-2026-46309 affects versions of the Linux kernel with the drm/xe/uapi component prior to the fix applied on June 8, 2026.

5

What does CVE-2026-46309 address specifically?

CVE-2026-46309 addresses a validation issue in the madvise function that allows rejecting invalid PAT indices with XE_COH_NONE coherency mode for CPU cached memory.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203