Bug 2513448 (CVE-2026-68103) - CVE-2026-68103 kernel: drm/amdgpu: reject mapping a reserved doorbell to a new queue
Summary: CVE-2026-68103 kernel: drm/amdgpu: reject mapping a reserved doorbell to a ne...
Keywords:
Status: NEW
Alias: CVE-2026-68103
Product: Security Response
Classification: Other
Component: vulnerability
Version: unspecified
Hardware: All
OS: Linux
medium
medium
Target Milestone: ---
Assignee: Product Security
QA Contact:
URL:
Whiteboard:
Depends On:
Blocks:
TreeView+ depends on / blocked
 
Reported: 2026-08-10 12:37 UTC by OSIDB Bzimport
Modified: 2026-08-11 11:57 UTC (History)
2 users (show)

Fixed In Version:
Clone Of:
Environment:
Last Closed:
Embargoed:


Attachments (Terms of Use)

Description OSIDB Bzimport 2026-08-10 12:37:56 UTC
In the Linux kernel, the following vulnerability has been resolved:

drm/amdgpu: reject mapping a reserved doorbell to a new queue

When creating an user-queue, the user space
provides a doorbell BO handle and an offset within
the bo to obtain a doorbell.

However current implementation using xa_store_irq()
to store a doorbell, which allows a later queue created
with the same BO and offset parameters to overwrite an
existing queue and doorbell mapping.

This can cause problems like misrouting fence IRQ
processing to a wrong queue, and mislead the cleanup
process of one queue erasing the mapping of another queue.

This commit fixes this issue by replacing xa_store_irq with
xa_insert_irq, which rejects mapping a reserved
doorbell to a newly created queue

(cherry picked from commit 6244eae22966350db52faf9c1369d3b2ffc5de4e)

Comment 1 Mauro Matteo Cascella 2026-08-11 11:54:30 UTC
Upstream advisory:
https://lore.kernel.org/linux-cve-announce/2026081052-CVE-2026-68103-1fa4@gregkh/T


Note You need to log in before you can comment on or make changes to this bug.