CVE-2026-72358: drm/xe/pt: prevent invalid cursor access for purged BOs

Published Aug 15, 2026
·
Updated

In the Linux kernel, the following vulnerability has been resolved:

drm/xe/pt: prevent invalid cursor access for purged BOs

During a page table walk for binding, xeptstagebind() explicitly skips initializing the xerescursor for purged BOs, treating them similarly to NULL VMAs by only setting the cursor size.

However, xepthugeptepossible() and xeptscan64K() did not check if the BO was purged before attempting to walk the cursor using xeresdma() and xeresnext(). Because the cursor was left uninitialized for purged BOs, this falls through and triggers warnings like:

WARNING: drivers/gpu/drm/xe/xerescursor.h:274 at xeresnext

Fix this by explicitly checking if the BO is purged in both xepthugeptepossible() and xeptscan64K(), returning early just as we do for NULL VMAs, avoiding the invalid cursor accesses entirely.

As a precaution, also zero-initialize the cursor in xeptstagebind() to ensure we don't pass garbage data into the page table walkers if we ever hit a similar edge case in the future.

(cherry picked from commit 4c7b9c6ece32440e5a435a92076d049450cd2d2e)

Remediation

Recommended actions to resolve this vulnerability, in priority order.

  1. Configuration

    Apply the drm/xe patch logic to prevent invalid cursor access for purged BOs: explicitly zero-initialize the cursor in xe_pt_stage_bind() and, in the page-table walk helpers, ensure xe_pt_hugepte_possible() and xe_pt_scan_64K() return early / skip walking when the BO is purged, similar to the existing NULL VMA handling by only setting the cursor size (avoiding uninitialized xe_res_cursor data that triggers warnings at xe_res_next).

    Linux kernel DRM i915/xe? (drivers/gpu/drm/xe/pt) xe_res_cursor initialization for purged BOs = skip cursor initialization / zero-initialize cursor in xe_pt_stage_bind() and only set cursor size
  2. Compensating control

    If patching is not immediately possible, mitigate by avoiding code paths that bind or traverse page tables for purged BOs (since the warning is triggered during cursor/page-table walker operations).

Event History

Aug 15, 2026
CVE Published
via MITRE·05:55 AM
Data Sourced
via MITRE·05:55 AM
Description
Free Weekly Intel

Don't miss critical vulnerabilities

Join thousands of security professionals who receive our weekly digest of trending CVEs, zero-days, and exploited vulnerabilities.

No spam. Unsubscribe anytime.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203