Bug 2492830 (CVE-2026-53201)

Summary: CVE-2026-53201 kernel: Linux kernel: Information disclosure or denial of service in drm/xe due to improper TLB invalidation
Product: [Other] Security Response Reporter: OSIDB Bzimport <bzimport>
Component: vulnerabilityAssignee: Product Security <prodsec-ir-bot>
Status: NEW --- QA Contact:
Severity: high Docs Contact:
Priority: high    
Version: unspecifiedCC: rhel-process-autobot, watson-tool-maintainers
Target Milestone: ---Keywords: Security
Target Release: ---   
Hardware: All   
OS: Linux   
Whiteboard:
Fixed In Version: Doc Type: ---
Doc Text:
A flaw was found in the Linux kernel's `drm/xe` graphics driver. An optimization intended to skip execution queue schedule toggling during GPU suspend could bypass a critical GuC suspend operation. This bypass prevents the GPU from properly flushing Translation Lookaside Buffer (TLB) entries for invalidated user memory areas, particularly in specific virtual memory modes. A local attacker could exploit this to cause missed TLB invalidations and page faults, potentially leading to information disclosure or a denial of service.
Story Points: ---
Clone Of: Environment:
Last Closed: Type: ---
Regression: --- Mount Type: ---
Documentation: --- CRM:
Verified Versions: Category: ---
oVirt Team: --- RHEL 7.3 requirements from Atomic Host:
Cloudforms Team: --- Target Upstream Version:
Embargoed:

Description OSIDB Bzimport 2026-06-25 10:08:00 UTC
In the Linux kernel, the following vulnerability has been resolved:

Revert "drm/xe: Skip exec queue schedule toggle if queue is idle during suspend"

This reverts commit 8533051ce92015e9cc6f75e0d52119b9d91610b6.

The idle-skip optimization bypasses GuC suspend, so the GPU may not
perform the context switch that flushes TLB entries for invalidated
userptr VMAs. In LR/preempt-fence VM mode, this can lead to missed TLB
invalidation and page faults during userptr invalidation tests.

Restore unconditional schedule toggling on suspend so the context-switch
TLB flush is always performed.

This optimization will be reintroduced with a fix that does not skip
suspend in LR/preempt-fence VM mode.

(cherry picked from commit 6a1e7934d9a6cf46aecae00a99c2603d1295e170)

Comment 1 Mauro Matteo Cascella 2026-06-29 14:29:23 UTC
Upstream advisory:
https://lore.kernel.org/linux-cve-announce/2026062500-CVE-2026-53201-039c@gregkh/T