Description
In the Linux kernel, the following vulnerability has been resolved:

drm/xe: Reject page faults from non-fault-mode scratch VMs

Having scratch enabled does not make a VM capable of handling recoverable
page faults. Allowing scratch VMs through the ASID lookup also admits
dma-fence mode VMs.

If such a VM faults on an already valid VMA, the handler reports success
without fixing the fault, causing the GPU to retry indefinitely.

Only allow fault-mode VMs through the ASID lookup. Fault-mode VMs using
scratch remain supported, while faults from 3D VMs are rejected.

(cherry picked from commit bfb24a06405b652d37831f3fb66b71d33a6605de)
Published: 2026-09-17
Score: n/a
EPSS: < 1% Very Low
KEV: No
Impact: Denial of Service
Action: Apply patch
AI Analysis

Impact

A flaw in the Linux kernel DRM driver for Xe GPUs allows non-fault-mode scratch virtual machines to trigger page faults that are reported as successful without being resolved. When such a fault occurs on a valid virtual memory area, the handler fails to recover the fault, causing the GPU to retry the operation indefinitely. This results in the GPU being stuck in a retry loop and can lead to a system or application hang, representing a denial‑of‑service vulnerability. The weakness is a logic error in the ASID lookup that incorrectly accepts non‑fault‑mode VMs.

Affected Systems

The vulnerability affects the generic Linux kernel (Linux:Linux) on systems that use the DRM/xe GPU driver. No specific kernel version is listed, so any installation that includes the affected driver and has been built before the patch that adds the ASID check will be vulnerable.

Risk and Exploitability

The EPSS score is below 1%, indicating a very low exploitation probability, and the vulnerability is not listed in CISA's KEV catalog, suggesting no known active exploits. The likely attack vector is local, requiring a privileged or kernel module that can create or manipulate scratch VMs. An attacker would need to trigger the fault condition on a page backed by a scratch VM to force the GPU into its infinite retry loop.

Generated by OpenCVE AI on September 20, 2026 at 04:31 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Apply the latest Linux kernel update that includes the commit adding the ASID lookup restriction for scratch VMs.
  • If an update cannot be applied immediately, disable scratch VM support or enforce fault‑mode checks in the driver configuration to prevent non‑fault‑mode VMs from being added to the ASID table.
  • Regularly monitor GPU driver logs for repeated page‑fault retries and associate them with a potential denial‑of‑service condition; reboot or halt the affected application if the issue persists.

Generated by OpenCVE AI on September 20, 2026 at 04:31 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Sun, 20 Sep 2026 05:00:00 +0000

Type Values Removed Values Added
Weaknesses CWE-20
CWE-399

Thu, 17 Sep 2026 16:30:00 +0000

Type Values Removed Values Added
Description In the Linux kernel, the following vulnerability has been resolved: drm/xe: Reject page faults from non-fault-mode scratch VMs Having scratch enabled does not make a VM capable of handling recoverable page faults. Allowing scratch VMs through the ASID lookup also admits dma-fence mode VMs. If such a VM faults on an already valid VMA, the handler reports success without fixing the fault, causing the GPU to retry indefinitely. Only allow fault-mode VMs through the ASID lookup. Fault-mode VMs using scratch remain supported, while faults from 3D VMs are rejected. (cherry picked from commit bfb24a06405b652d37831f3fb66b71d33a6605de)
Title drm/xe: Reject page faults from non-fault-mode scratch VMs
First Time appeared Linux
Linux linux Kernel
CPEs cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*
Vendors & Products Linux
Linux linux Kernel
References

Subscriptions

Linux Linux Kernel
cve-icon MITRE

Status: PUBLISHED

Assigner: Linux

Published:

Updated: 2026-09-17T16:05:47.607Z

Reserved: 2026-09-11T19:38:34.784Z

Link: CVE-2026-90064

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Received

Published: 2026-09-17T17:16:55.220

Modified: 2026-09-17T17:16:55.220

Link: CVE-2026-90064

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-20T04:45:16Z

Weaknesses