CVE-2026-64590

Linux kernel (GCP) vulnerabilities

Beschreibung

Im Linux-Kernel wurde folgende Schwachstelle behoben:

dma-buf/udmabuf: Überspringe redundante CPU-Synchronisation, um Warnung "cacheline EEXIST" zu beheben

Wenn CONFIG_DMA_API_DEBUG_SG aktiviert ist, löst das Importieren eines udmabufs in einen DRM-Treiber (z. B. amdgpu für Videowiedergabe in GNOME Videos / Showtime) eine irreführende Warnung aus:

DMA-API: amdgpu 0000:03:00.0: cacheline tracking EEXIST, überlappende Zuordnungen werden nicht unterstützt
WARNUNG: kernel/dma/debug.c:619 at add_dma_entry+0x473/0x5f0

Die Aufrufkette ist:

amdgpu_cs_ioctl -> amdgpu_ttm_backend_bind -> dma_buf_map_attachment -> [udmabuf] map_udmabuf -> get_sg_table -> dma_map_sgtable(dev, sg, direction, 0) // attrs=0 -> debug_dma_map_sg -> add_dma_entry -> EEXIST

Dies geschieht, weil udmabuf eine pro-Seiten-Scatter-Gather-Liste über sg_set_folio() erstellt. Wenn begin_cpu_udmabuf() bereits eine sg-Tabelle für das Gerät misc erstellt hat und ein Importeur wie amdgpu dieselben Seiten für sein eigenes Gerät über map_udmabuf() zuordnet, sieht die DMA-Debug-Infrastruktur zwei aktive Zuordnungen mit physischen Adressen, die sich an Cachelinien-Grenzen überschneiden, und warnt vor der Überlappung.

Die Flagge DMA_ATTR_SKIP_CPU_SYNC unterdrückt diese Prüfung in add_dma_entry(), da sie signalisiert, dass keine CPU-Cache-Wartung bei map/unmap-Zeit durchgeführt wird, wodurch die Cachelinien-Überlappung harmlos ist.

Alle anderen wichtigen dma-buf-Exporteure übergeben bereits diese Flagge:

  • drm_gem_map_dma_buf() übergibt DMA_ATTR_SKIP_CPU_SYNC
  • amdgpu_dma_buf_map() übergibt DMA_ATTR_SKIP_CPU_SYNC

Die CPU-Synchronisation bei map/unmap-Zeit ist auch für udmabuf redundant: begin_cpu_udmabuf() und end_cpu_udmabuf() führen eine explizite Cache-Synchronisation über dma_sync_sgtable_for_cpu/device() durch, wenn der CPU-Zugriff über die dma-buf-Schnittstelle angefordert wird.

Übergebe DMA_ATTR_SKIP_CPU_SYNC an dma_map_sgtable() und dma_unmap_sgtable() in udmabuf, um die irreführende Warnung zu unterdrücken und die redundante Synchronisation zu überspringen.

Metriken

Severity
high
kein öffentlicher PoC bekannt
7.1
Quelle: cna-v3
6.0 %
Niedrig — CVE gehört zu den unteren 10 % der heute bewerteten CVEs.
0.2 %
Niedrig — Modell schätzt < 1 % Ausnutzungs-Wahrscheinlichkeit.
Veröffentlicht
2026-09-07 09:05 UTC

Re-Analyse & Statuswechsel

Chronologie der NVD-Audit-Events für diese CVE — Reanalyses, CVSS-Updates, CPE-Diffs.

  1. CVE Modified2026-08-23 13:16 UTC· 416baaa9-dc9f-4396-8d5f-8c081fb06d67
    • Reference: https://git.kernel.org/stable/c/01126abc11bcc6a45b664293b0b5df715be911d7
    • Reference: https://git.kernel.org/stable/c/4a7c644e632741c2a3116a0d3da6c11de957a6ba
    • Reference: https://git.kernel.org/stable/c/dd7f1e572f44d3d039dc77e3989f537196c3bf52
    • Affected: Linux, LinuxLinux, Linux
  2. CVE Modified2026-08-17 05:18 UTC· 416baaa9-dc9f-4396-8d5f-8c081fb06d67
    • Affected: Linux, LinuxLinux, Linux
  3. New CVE Received2026-08-06 08:16 UTC· 416baaa9-dc9f-4396-8d5f-8c081fb06d67
    • Affected: Linux, Linux
    • Description: In the Linux kernel, the following vulnerability has been resolved: dma-buf/udmabuf: skip redundant cpu sync to fix cacheline EEXIST warning When CONFIG_DMA_API_DEBUG_SG is enabled, importing a udmabuf into a DRM driver (e.g. amdgpu for video playback in GNOME Videos / Showtime) triggers a spurious warning: DMA-API: amdgpu 0000:03:00.0: cacheline tracking EEXIST, \ overlapping mappings aren't supported WARNING: kernel/dma/debug.c:619 at add_dma_entry+0x473/0x5f0 The call chain is: amdgpu_cs_ioctl -> amdgpu_ttm_backend_bind -> dma_buf_map_attachment -> [udmabuf] map_udmabuf -> get_sg_table -> dma_map_sgtable(dev, sg, direction, 0) // attrs=0 -> debug_dma_map_sg -> add_dma_entry -> EEXIST This happens because udmabuf builds a per-page scatter-gather list via sg_set_folio(). When begin_cpu_udmabuf() has already created an sg table mapped for the misc device, and an importer such as amdgpu maps the same pages for its own device via map_udmabuf(), the DMA debug infrastructure sees two active mappings whose physical addresses share cacheline boundaries and warns about the overlap. The DMA_ATTR_SKIP_CPU_SYNC flag suppresses this check in add_dma_entry() because it signals that no CPU cache maintenance is performed at map/unmap time, making the cacheline overlap harmless. All other major dma-buf exporters already pass this flag: - drm_gem_map_dma_buf() passes DMA_ATTR_SKIP_CPU_SYNC - amdgpu_dma_buf_map() passes DMA_ATTR_SKIP_CPU_SYNC The CPU sync at map/unmap time is also redundant for udmabuf: begin_cpu_udmabuf() and end_cpu_udmabuf() already perform explicit cache synchronization via dma_sync_sgtable_for_cpu/device() when CPU access is requested through the dma-buf interface. Pass DMA_ATTR_SKIP_CPU_SYNC to dma_map_sgtable() and dma_unmap_sgtable() in udmabuf to suppress the spurious warning and skip the redundant sync.
    • Reference: https://git.kernel.org/stable/c/0449a6583c0ee76778d314e4e82f166fc97fa9d8
    • Reference: https://git.kernel.org/stable/c/0db56e7eae932f8e2f3eb44ad1a63633d8f504f8

Betroffene Betriebssysteme

  • linux

    redhat / enterprise_linux10.0

  • linux

    redhat / enterprise_linux7.0

  • linux

    redhat / enterprise_linux8.0

  • linux

    redhat / enterprise_linux9.0

  • linux

    ubuntu / linux-aws-6.8jammy

  • linux

    ubuntu / linux-azureresolute

  • linux

    ubuntu / linux-azuretrusty

  • linux

    ubuntu / linux-azurexenial

  • linux

    ubuntu / linux-azure-4.15bionic

  • linux

    ubuntu / linux-azure-5.4bionic

  • linux

    ubuntu / linux-azure-fdenoble

  • linux

    ubuntu / linux-azure-fderesolute

  • linux

    ubuntu / linux-azure-fde-6.8jammy

  • linux

    ubuntu / linux-azure-fipsbionic

  • linux

    ubuntu / linux-azure-fipsfocal

  • linux

    ubuntu / linux-azure-fipsnoble

  • linux

    ubuntu / linux-fipsjammy

  • linux

    ubuntu / linux-gcp-7.0noble

  • linux

    ubuntu / linux-gkejammy

  • linux

    ubuntu / linux-nvidia-tegranoble

  • linux

    ubuntu / linux-raspinoble

  • linux

    ubuntu / linux-raspi-realtimenoble

  • linux

    linux / linux_kernel2.6.12

  • linux

    linux / linux_kernel2.6.15

Quellen & Referenzen

Verknüpfte CVEs

1392 weitere CVEs anzeigen
IDCVE-2026-64590
Linux kernel (GCP) vulnerabilities — CVE-2026-64590 | NEOSEC Intel