Bug 2516775 (CVE-2026-74420)

Summary: CVE-2026-74420 kernel: drm/gpusvm: Reject VMAs with VM_IO or VM_PFNMAP when creating SVM ranges
Product: [Other] Security Response Reporter: OSIDB Bzimport <bzimport>
Component: vulnerabilityAssignee: Product Security DevOps Team <prodsec-dev>
Status: NEW --- QA Contact:
Severity: medium Docs Contact:
Priority: medium    
Version: unspecifiedCC: rhel-process-autobot, watson-tool-maintainers
Target Milestone: ---Keywords: Security
Target Release: ---   
Hardware: All   
OS: Linux   
Whiteboard:
Fixed In Version: Doc Type: ---
Doc Text:
A flaw was found in the Linux kernel's GPU Shared Virtual Memory (SVM) subsystem. This vulnerability occurs when attempting to create an SVM range on Virtual Memory Areas (VMAs) that are not backed by physical page objects. An attacker could exploit this by triggering repeated page retrieval failures, leading to an infinite loop within a driver's page-fault handler. This can result in a system-wide Denial of Service (DoS).
Story Points: ---
Clone Of: Environment:
Last Closed: Type: ---
Regression: --- Mount Type: ---
Documentation: --- CRM:
Verified Versions: Category: ---
oVirt Team: --- RHEL 7.3 requirements from Atomic Host:
Cloudforms Team: --- Target Upstream Version:
Embargoed:

Description OSIDB Bzimport 2026-08-15 06:32:50 UTC
In the Linux kernel, the following vulnerability has been resolved:

drm/gpusvm: Reject VMAs with VM_IO or VM_PFNMAP when creating SVM ranges

VMAs marked with VM_IO or VM_PFNMAP are not backed by struct page
objects, which GPUSVM requires in order to operate correctly. In
particular, get_pages() relies on hmm_range_fault() to resolve struct
pages for the target range.

Attempting to create an SVM range on such VMAs results in repeated
get_pages() failures and can lead to an infinite loop inside a driver’s
page‑fault handler. Prevent this by rejecting ranges on VM_IO or
VM_PFNMAP VMAs and returning -EIO.