Description
In the Linux kernel, the following vulnerability has been resolved:

drm/panthor: Add vm_bind region with kbo range overlap check

When a VM is created, caller has to specify the range of the address space
carve-out set aside for mapping kernel BO's. That means vm_bind mappings of
UM-exposed BO's should not intersect with that region, but at the moment
we're not checking this.

At first, I thought of giving these values to drm_gpuvm_init() through its
reserve_{offset, range} arguments, but it turns out that is meant for VM
address spans that are not managed through the usual drm_gpuvm split/merge
circuit, so storing the end of the user VA range at VM creation time and
doing a quick check in the vm_bind ioctl path was the simplest workaround.

The new check also makes sure vm_bind range doesn't overflow the size of a
64-bit unsigned integer. That was already being done further down the call
stack inside drm_gpuvm_sm_map -> drm_gpuvm_range_valid, but it's best to
fail early in the driver before GPUVM functions are invoked so that we
won't waste time allocating vm_bind context resources.
Published: 2026-09-17
Score: n/a
EPSS: < 1% Very Low
KEV: No
Impact: Privilege Escalation and Memory Corruption Potential
Action: Patch Now
AI Analysis

Impact

The flaw arises from missing validation in the DRM panthor driver that allows a user process to request a vm_bind mapping whose address range can overlap the carve‑out region reserved for kernel buffer objects. Because the kernel does not check for this overlap, a malicious actor could create a mapping that touches kernel memory used by driver objects, potentially corrupting data or writing to privileged memory. In addition the code previously permitted arithmetic overflow of the 64‑bit mapping range, which could also lead to unexpected behaviour. As described, no immediate exploit path is detailed, but the unchecked overlap and overflow together raise the possibility of memory corruption that could be leveraged for privilege escalation.

Affected Systems

All Linux kernel builds that ship the panthor DRM driver in an unpatched state are affected. The vulnerability is kernel‑level and vendor independent, so any distribution running a kernel prior to the patch that contains this driver code must be considered vulnerable. No specific version range is provided; all susceptible builds before the fix are included.

Risk and Exploitability

The EPSS score is below 1%, indicating an overall low probability of exploitation in the wild, and the vulnerability is not listed in the CISA KEV catalog. The likely attack vector is local, via the privileged drm_gpuvm_bind ioctl, and would require a user process with the ability to invoke this ioctl to craft overlapping mappings. Although the advisory does not describe a proven exploit, the unchecked overlap and potential integer overflow create a plausible avenue for memory corruption and possibly privilege escalation if the attacker can manipulate the mapping range.

Generated by OpenCVE AI on September 19, 2026 at 13:17 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Update to a kernel version that includes the patch implementing the overlap and overflow checks in the panthor DRM driver.
  • Adjust or audit applications that use vm_bind to ensure that requested offset and range values do not intersect the kernel buffer object carve‑out region before issuing the ioctl.
  • Enable kernel debugging or increase verbosity for the DRM subsystem so that mapping failures are logged promptly for early detection of misconfigurations.

Generated by OpenCVE AI on September 19, 2026 at 13:17 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Sat, 19 Sep 2026 13:45:00 +0000

Type Values Removed Values Added
Weaknesses CWE-190
CWE-284

Thu, 17 Sep 2026 16:30:00 +0000

Type Values Removed Values Added
Description In the Linux kernel, the following vulnerability has been resolved: drm/panthor: Add vm_bind region with kbo range overlap check When a VM is created, caller has to specify the range of the address space carve-out set aside for mapping kernel BO's. That means vm_bind mappings of UM-exposed BO's should not intersect with that region, but at the moment we're not checking this. At first, I thought of giving these values to drm_gpuvm_init() through its reserve_{offset, range} arguments, but it turns out that is meant for VM address spans that are not managed through the usual drm_gpuvm split/merge circuit, so storing the end of the user VA range at VM creation time and doing a quick check in the vm_bind ioctl path was the simplest workaround. The new check also makes sure vm_bind range doesn't overflow the size of a 64-bit unsigned integer. That was already being done further down the call stack inside drm_gpuvm_sm_map -> drm_gpuvm_range_valid, but it's best to fail early in the driver before GPUVM functions are invoked so that we won't waste time allocating vm_bind context resources.
Title drm/panthor: Add vm_bind region with kbo range overlap check
First Time appeared Linux
Linux linux Kernel
CPEs cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*
Vendors & Products Linux
Linux linux Kernel
References

Subscriptions

Linux Linux Kernel
cve-icon MITRE

Status: PUBLISHED

Assigner: Linux

Published:

Updated: 2026-09-17T16:09:36.740Z

Reserved: 2026-09-11T19:38:34.812Z

Link: CVE-2026-90409

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Received

Published: 2026-09-17T17:17:40.800

Modified: 2026-09-17T17:17:40.800

Link: CVE-2026-90409

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-19T13:30:13Z

Weaknesses
  • CWE-190

    Integer Overflow or Wraparound

  • CWE-284

    Improper Access Control