CVE-2026-72358: drm/xe/pt: prevent invalid cursor access for purged BOs
In the Linux kernel, the following vulnerability has been resolved:
drm/xe/pt: prevent invalid cursor access for purged BOs
During a page table walk for binding, xeptstagebind() explicitly skips initializing the xerescursor for purged BOs, treating them similarly to NULL VMAs by only setting the cursor size.
However, xepthugeptepossible() and xeptscan64K() did not check if the BO was purged before attempting to walk the cursor using xeresdma() and xeresnext(). Because the cursor was left uninitialized for purged BOs, this falls through and triggers warnings like:
WARNING: drivers/gpu/drm/xe/xerescursor.h:274 at xeresnext
Fix this by explicitly checking if the BO is purged in both xepthugeptepossible() and xeptscan64K(), returning early just as we do for NULL VMAs, avoiding the invalid cursor accesses entirely.
As a precaution, also zero-initialize the cursor in xeptstagebind() to ensure we don't pass garbage data into the page table walkers if we ever hit a similar edge case in the future.
(cherry picked from commit 4c7b9c6ece32440e5a435a92076d049450cd2d2e)
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Configuration
Apply the drm/xe patch logic to prevent invalid cursor access for purged BOs: explicitly zero-initialize the cursor in xe_pt_stage_bind() and, in the page-table walk helpers, ensure xe_pt_hugepte_possible() and xe_pt_scan_64K() return early / skip walking when the BO is purged, similar to the existing NULL VMA handling by only setting the cursor size (avoiding uninitialized xe_res_cursor data that triggers warnings at xe_res_next).
Linux kernel DRM i915/xe? (drivers/gpu/drm/xe/pt) xe_res_cursor initialization for purged BOs = skip cursor initialization / zero-initialize cursor in xe_pt_stage_bind() and only set cursor size - Compensating control
If patching is not immediately possible, mitigate by avoiding code paths that bind or traverse page tables for purged BOs (since the warning is triggered during cursor/page-table walker operations).