{
  "affected": [
    {
      "ranges": [
        {
          "events": [
            {
              "introduced": "9e978741488261e117bb50e5dfcf8e4080990958"
            },
            {
              "fixed": "f9a9abd7bbdab3dfe1b1155e1457dc02b5e14ea5"
            },
            {
              "fixed": "ab9ea5c943c7e780124e75b7ffad9f1c752b2579"
            },
            {
              "fixed": "dca6e08c923a44d2d66b955e03dd57a3a38c2b94"
            }
          ],
          "repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
          "type": "GIT"
        }
      ]
    },
    {
      "package": {
        "ecosystem": "Linux",
        "name": "Kernel"
      },
      "ranges": [
        {
          "events": [
            {
              "introduced": "6.18.0"
            },
            {
              "fixed": "6.18.40"
            }
          ],
          "type": "ECOSYSTEM"
        },
        {
          "events": [
            {
              "introduced": "6.19.0"
            },
            {
              "fixed": "7.1.5"
            }
          ],
          "type": "ECOSYSTEM"
        }
      ]
    }
  ],
  "database_specific": {
    "cna_assigner": "Linux",
    "osv_generated_from": "https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/80xxx/CVE-2026-80606.json"
  },
  "details": "In the Linux kernel, the following vulnerability has been resolved:\n\ndrm/xe/userptr: Hold notifier_lock for write on inject test path\n\nWhen CONFIG_DRM_XE_USERPTR_INVAL_INJECT=y, xe_pt_svm_userptr_pre_commit()\nruns vma_check_userptr() with the svm notifier_lock taken for read. The\ntest injection causes vma_check_userptr() to call\nxe_vma_userptr_force_invalidate(), which feeds into\nxe_vma_userptr_do_inval() with drm_gpusvm_ctx.in_notifier=true. That\nflag tells drm_gpusvm_unmap_pages() the caller already holds\nnotifier_lock for write and only asserts the mode. Because the caller\nactually holds it for read, the assertion fires:\n\n  WARNING: drivers/gpu/drm/drm_gpusvm.c:1669 at \\\n           drm_gpusvm_unmap_pages+0xd4/0x130 [drm_gpusvm_helper]\n  Call Trace:\n   xe_vma_userptr_do_inval+0x40d/0xfd0 [xe]\n   xe_vma_userptr_invalidate_pass1+0x3e6/0x8d0 [xe]\n   xe_vma_userptr_force_invalidate+0xde/0x290 [xe]\n   vma_check_userptr.constprop.0+0x1c6/0x220 [xe]\n   xe_pt_svm_userptr_pre_commit+0x6a3/0xc60 [xe]\n   ...\n   xe_vm_bind_ioctl+0x3a0a/0x4480 [xe]\n\nAcquire notifier_lock for write in pre-commit when the inject Kconfig\nis enabled, via new helpers xe_pt_svm_userptr_notifier_lock()/_unlock().\nRename xe_svm_assert_held_read() to\nxe_svm_assert_held_read_or_inject_write() so it asserts the correct\nmode under each build configuration. Production builds\n(CONFIG_DRM_XE_USERPTR_INVAL_INJECT=n) keep the existing read-mode\nbehavior bit-for-bit.\n\n(cherry picked from commit 80ccbd97ffee8ad2e73167d826fe7be548364365)",
  "id": "CVE-2026-80606",
  "modified": "2026-08-31T03:30:39.134994898Z",
  "published": "2026-08-28T06:48:30.960Z",
  "references": [
    {
      "type": "WEB",
      "url": "https://git.kernel.org/stable/c/ab9ea5c943c7e780124e75b7ffad9f1c752b2579"
    },
    {
      "type": "WEB",
      "url": "https://git.kernel.org/stable/c/dca6e08c923a44d2d66b955e03dd57a3a38c2b94"
    },
    {
      "type": "WEB",
      "url": "https://git.kernel.org/stable/c/f9a9abd7bbdab3dfe1b1155e1457dc02b5e14ea5"
    },
    {
      "type": "ADVISORY",
      "url": "https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/80xxx/CVE-2026-80606.json"
    },
    {
      "type": "ADVISORY",
      "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-80606"
    },
    {
      "type": "PACKAGE",
      "url": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git"
    }
  ],
  "schema_version": "1.9.0",
  "severity": [
    {
      "score": "CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:C/C:H/I:H/A:H",
      "type": "CVSS_V3"
    }
  ],
  "summary": "drm/xe/userptr: Hold notifier_lock for write on inject test path"
}