CVE-2025-40166 (GCVE-0-2025-40166)
Vulnerability from cvelistv5
Published
2025-11-12 10:26
Modified
2026-08-05 12:08
Summary
In the Linux kernel, the following vulnerability has been resolved: drm/xe/guc: Check GuC running state before deregistering exec queue In normal operation, a registered exec queue is disabled and deregistered through the GuC, and freed only after the GuC confirms completion. However, if the driver is forced to unbind while the exec queue is still running, the user may call exec_destroy() after the GuC has already been stopped and CT communication disabled. In this case, the driver cannot receive a response from the GuC, preventing proper cleanup of exec queue resources. Fix this by directly releasing the resources when GuC is not running. Here is the failure dmesg log: " [ 468.089581] ---[ end trace 0000000000000000 ]--- [ 468.089608] pci 0000:03:00.0: [drm] *ERROR* GT0: GUC ID manager unclean (1/65535) [ 468.090558] pci 0000:03:00.0: [drm] GT0: total 65535 [ 468.090562] pci 0000:03:00.0: [drm] GT0: used 1 [ 468.090564] pci 0000:03:00.0: [drm] GT0: range 1..1 (1) [ 468.092716] ------------[ cut here ]------------ [ 468.092719] WARNING: CPU: 14 PID: 4775 at drivers/gpu/drm/xe/xe_ttm_vram_mgr.c:298 ttm_vram_mgr_fini+0xf8/0x130 [xe] " v2: use xe_uc_fw_is_running() instead of xe_guc_ct_enabled(). As CT may go down and come back during VF migration. (cherry picked from commit 9b42321a02c50a12b2beb6ae9469606257fbecea)
Impacted products
Vendor Product Version
Linux Linux Version: dd08ebf6c3525a7ea2186e636df064ea47281987
Version: dd08ebf6c3525a7ea2186e636df064ea47281987
Version: dd08ebf6c3525a7ea2186e636df064ea47281987
Create a notification for this product.
Show details on NVD website


{
  "containers": {
    "cna": {
      "affected": [
        {
          "defaultStatus": "unaffected",
          "product": "Linux",
          "programFiles": [
            "drivers/gpu/drm/xe/xe_guc_submit.c"
          ],
          "repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
          "vendor": "Linux",
          "versions": [
            {
              "lessThan": "2c6e5904c5bdbac8e0eadee40f70c42bb83f6dc6",
              "status": "affected",
              "version": "dd08ebf6c3525a7ea2186e636df064ea47281987",
              "versionType": "git"
            },
            {
              "lessThan": "fa708415566bbe5361c935645107319f8edc8dc1",
              "status": "affected",
              "version": "dd08ebf6c3525a7ea2186e636df064ea47281987",
              "versionType": "git"
            },
            {
              "lessThan": "9f64b3cd051b825de0a2a9f145c8e003200cedd5",
              "status": "affected",
              "version": "dd08ebf6c3525a7ea2186e636df064ea47281987",
              "versionType": "git"
            }
          ]
        },
        {
          "defaultStatus": "affected",
          "product": "Linux",
          "programFiles": [
            "drivers/gpu/drm/xe/xe_guc_submit.c"
          ],
          "repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
          "vendor": "Linux",
          "versions": [
            {
              "status": "affected",
              "version": "6.8"
            },
            {
              "lessThan": "6.8",
              "status": "unaffected",
              "version": "0",
              "versionType": "semver"
            },
            {
              "lessThanOrEqual": "6.12.*",
              "status": "unaffected",
              "version": "6.12.55",
              "versionType": "semver"
            },
            {
              "lessThanOrEqual": "6.17.*",
              "status": "unaffected",
              "version": "6.17.5",
              "versionType": "semver"
            },
            {
              "lessThanOrEqual": "*",
              "status": "unaffected",
              "version": "6.18",
              "versionType": "original_commit_for_fix"
            }
          ]
        }
      ],
      "cpeApplicability": [
        {
          "nodes": [
            {
              "cpeMatch": [
                {
                  "criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
                  "versionEndExcluding": "6.12.55",
                  "versionStartIncluding": "6.8",
                  "vulnerable": true
                },
                {
                  "criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
                  "versionEndExcluding": "6.17.5",
                  "versionStartIncluding": "6.8",
                  "vulnerable": true
                },
                {
                  "criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
                  "versionEndExcluding": "6.18",
                  "versionStartIncluding": "6.8",
                  "vulnerable": true
                }
              ],
              "negate": false,
              "operator": "OR"
            }
          ]
        }
      ],
      "descriptions": [
        {
          "lang": "en",
          "value": "In the Linux kernel, the following vulnerability has been resolved:\n\ndrm/xe/guc: Check GuC running state before deregistering exec queue\n\nIn normal operation, a registered exec queue is disabled and\nderegistered through the GuC, and freed only after the GuC confirms\ncompletion. However, if the driver is forced to unbind while the exec\nqueue is still running, the user may call exec_destroy() after the GuC\nhas already been stopped and CT communication disabled.\n\nIn this case, the driver cannot receive a response from the GuC,\npreventing proper cleanup of exec queue resources. Fix this by directly\nreleasing the resources when GuC is not running.\n\nHere is the failure dmesg log:\n\"\n[  468.089581] ---[ end trace 0000000000000000 ]---\n[  468.089608] pci 0000:03:00.0: [drm] *ERROR* GT0: GUC ID manager unclean (1/65535)\n[  468.090558] pci 0000:03:00.0: [drm] GT0:     total 65535\n[  468.090562] pci 0000:03:00.0: [drm] GT0:     used 1\n[  468.090564] pci 0000:03:00.0: [drm] GT0:     range 1..1 (1)\n[  468.092716] ------------[ cut here ]------------\n[  468.092719] WARNING: CPU: 14 PID: 4775 at drivers/gpu/drm/xe/xe_ttm_vram_mgr.c:298 ttm_vram_mgr_fini+0xf8/0x130 [xe]\n\"\n\nv2: use xe_uc_fw_is_running() instead of xe_guc_ct_enabled().\n    As CT may go down and come back during VF migration.\n\n(cherry picked from commit 9b42321a02c50a12b2beb6ae9469606257fbecea)"
        }
      ],
      "metrics": [
        {
          "cvssV3_1": {
            "baseScore": 7.8,
            "baseSeverity": "HIGH",
            "vectorString": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H",
            "version": "3.1"
          },
          "scenarios": [
            {
              "lang": "en",
              "value": "AV:L - The vulnerable code is reached only through the local DRM character device \u2014 `ioctl(DRM_IOCTL_XE_EXEC_QUEUE_DESTROY)` on `/dev/dri/renderD*` or closing that fd via `xe_file_close()`; no network or adjacent-network input feeds `__guc_exec_queue_process_msg_cleanup()`.\nAC:L - There is no race for the attacker to win \u2014 once the GuC firmware is no longer marked running (driver unbind, PCI hot-unplug of a Thunderbolt/USB4 eGPU, FLR-based shutdown, or CT teardown), every cleanup of a still-registered exec queue deterministically takes the broken `disable_scheduling_deregister()` branch, and the attacker simply keeps a submitted exec queue alive so its destruction lands in that window.\nPR:L - `XE_EXEC_QUEUE_DESTROY` and `XE_EXEC_QUEUE_CREATE` are registered with `DRM_RENDER_ALLOW` and perform no capability check, so any unprivileged local account in the `render`/`video` group \u2014 including a container or sandbox given `/dev/dri` passthrough \u2014 can create and destroy exec queues.\nUI:N - The triggering action is entirely the attacker\u0027s own \u2014 an `exec_destroy()` ioctl or simply exiting the process so `xe_file_close()` tears down its queues \u2014 and the device-teardown side occurs on ordinary system events (shutdown/FLR, hot-unplug, driver reload) rather than requiring a separate victim to perform an action.\nS:U - The leaked exec queue, stale GuC IDs, dangling TTM VRAM manager and subsequent stale-work dereferences are all confined to the host kernel\u0027s own memory and the same security authority; no hypervisor, IOMMU, or sandbox boundary is crossed.\nC:H - Because `__guc_exec_queue_destroy_async()` \u2014 explicitly commented \"Confirm no work left behind accessing device structures\" \u2014 never runs, the DRM scheduler\u0027s `work_tdr` delayed work stays armed on a leaked `xe_guc_exec_queue` and later dereferences the drmm-freed `xe_device`/`xe_gt`/`xe_guc`, a use-after-free read of reclaimed kernel memory that an attacker can groom with heap spraying; the leaked LRC/ring VRAM objects are likewise never scrubbed or returned to the allocator.\nI:H - The same never-cancelled TDR work and never-fini\u0027d `drm_gpu_scheduler`/entity fire against freed device structures \u2014 and after `rmmod xe` against freed module text \u2014 giving a write and control-flow hijack primitive over reclaimed memory, while `ttm_vram_mgr_fini()`\u0027s early return leaves a stale `ttm_resource_manager` pointer registered in the freed `xe_device`.\nA:H - The bug reliably produces kernel WARN/assert splats (`xe_gt_assert` in `guc_submit_fini()` and `WARN_ON_ONCE` in `ttm_vram_mgr_fini()`, fatal on `panic_on_warn` systems), permanently leaks GuC IDs and VRAM so the GPU cannot be rebound without a reboot, and leaves `xe_drm_client_fdinfo()`\u0027s untimed `wait_var_event()` on `pending_removal` blocking forever, producing an unkillable uninterruptible-sleep task."
            }
          ]
        }
      ],
      "providerMetadata": {
        "dateUpdated": "2026-08-05T12:08:11.302Z",
        "orgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
        "shortName": "Linux"
      },
      "references": [
        {
          "url": "https://git.kernel.org/stable/c/2c6e5904c5bdbac8e0eadee40f70c42bb83f6dc6"
        },
        {
          "url": "https://git.kernel.org/stable/c/fa708415566bbe5361c935645107319f8edc8dc1"
        },
        {
          "url": "https://git.kernel.org/stable/c/9f64b3cd051b825de0a2a9f145c8e003200cedd5"
        }
      ],
      "title": "drm/xe/guc: Check GuC running state before deregistering exec queue",
      "x_generator": {
        "engine": "bippy-1.2.0"
      }
    }
  },
  "cveMetadata": {
    "assignerOrgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
    "assignerShortName": "Linux",
    "cveId": "CVE-2025-40166",
    "datePublished": "2025-11-12T10:26:24.143Z",
    "dateReserved": "2025-04-16T07:20:57.176Z",
    "dateUpdated": "2026-08-05T12:08:11.302Z",
    "state": "PUBLISHED"
  },
  "dataType": "CVE_RECORD",
  "dataVersion": "5.2"
}


Log in or create an account to share your comment.




Tags
Taxonomy of the tags.


Loading…

Loading…

Loading…

Sightings

Author Source Type Date

Nomenclature

  • Seen: The vulnerability was mentioned, discussed, or seen somewhere by the user.
  • Confirmed: The vulnerability is confirmed from an analyst perspective.
  • Published Proof of Concept: A public proof of concept is available for this vulnerability.
  • Exploited: This vulnerability was exploited and seen by the user reporting the sighting.
  • Patched: This vulnerability was successfully patched by the user reporting the sighting.
  • Not exploited: This vulnerability was not exploited or seen by the user reporting the sighting.
  • Not confirmed: The user expresses doubt about the veracity of the vulnerability.
  • Not patched: This vulnerability was not successfully patched by the user reporting the sighting.


Loading…

Loading…