{
  "affected": [
    {
      "ecosystem_specific": {
        "urgency": "not yet assigned"
      },
      "package": {
        "ecosystem": "Debian:14",
        "name": "linux"
      },
      "ranges": [
        {
          "events": [
            {
              "introduced": "0"
            },
            {
              "fixed": "7.1.5-1"
            }
          ],
          "type": "ECOSYSTEM"
        }
      ]
    }
  ],
  "details": "In the Linux kernel, the following vulnerability has been resolved:  drm/xe/userptr: Hold notifier_lock for write on inject test path  When CONFIG_DRM_XE_USERPTR_INVAL_INJECT=y, xe_pt_svm_userptr_pre_commit() runs vma_check_userptr() with the svm notifier_lock taken for read. The test injection causes vma_check_userptr() to call xe_vma_userptr_force_invalidate(), which feeds into xe_vma_userptr_do_inval() with drm_gpusvm_ctx.in_notifier=true. That flag tells drm_gpusvm_unmap_pages() the caller already holds notifier_lock for write and only asserts the mode. Because the caller actually holds it for read, the assertion fires:    WARNING: drivers/gpu/drm/drm_gpusvm.c:1669 at \\            drm_gpusvm_unmap_pages+0xd4/0x130 [drm_gpusvm_helper]   Call Trace:    xe_vma_userptr_do_inval+0x40d/0xfd0 [xe]    xe_vma_userptr_invalidate_pass1+0x3e6/0x8d0 [xe]    xe_vma_userptr_force_invalidate+0xde/0x290 [xe]    vma_check_userptr.constprop.0+0x1c6/0x220 [xe]    xe_pt_svm_userptr_pre_commit+0x6a3/0xc60 [xe]    ...    xe_vm_bind_ioctl+0x3a0a/0x4480 [xe]  Acquire notifier_lock for write in pre-commit when the inject Kconfig is enabled, via new helpers xe_pt_svm_userptr_notifier_lock()/_unlock(). Rename xe_svm_assert_held_read() to xe_svm_assert_held_read_or_inject_write() so it asserts the correct mode under each build configuration. Production builds (CONFIG_DRM_XE_USERPTR_INVAL_INJECT=n) keep the existing read-mode behavior bit-for-bit.  (cherry picked from commit 80ccbd97ffee8ad2e73167d826fe7be548364365)",
  "id": "DEBIAN-CVE-2026-80606",
  "modified": "2026-09-14T16:47:47.473653327Z",
  "published": "2026-08-28T08:16:44.573Z",
  "references": [
    {
      "type": "ADVISORY",
      "url": "https://security-tracker.debian.org/tracker/CVE-2026-80606"
    }
  ],
  "severity": [
    {
      "score": "CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:C/C:H/I:H/A:H",
      "type": "CVSS_V3"
    }
  ],
  "upstream": [
    "CVE-2026-80606"
  ]
}