Vulnerability Description
In the Linux kernel, the following vulnerability has been resolved: drm/gpusvm: publish dpagemap early to avoid device mapping leak on error drm_gpusvm_get_pages() only stored the local dpagemap into svm_pages->dpagemap on the success path. If a later page failed (e.g. -EOPNOTSUPP when ctx->allow_mixed is false) and jumped to err_unmap, svm_pages->dpagemap was still NULL, so __drm_gpusvm_unmap_pages() skipped device_unmap() and leaked the device mappings already created. Assign svm_pages->dpagemap when the first device page is mapped so the err_unmap path can device_unmap() those mappings. This issue was found by Sashiko AI review.
CVSS Score
HIGH
References
- https://git.kernel.org/stable/c/72e4fca5529e45b5beebad79d804de442f632324
- https://git.kernel.org/stable/c/7f708f51e3955bda0d77a0b67ab9bea6c97fea99
- https://git.kernel.org/stable/c/e8362523fd1b61712f7d996802f9b5dee545c7e6
FAQ
What is CVE-2026-68240?
CVE-2026-68240 is a vulnerability with a CVSS score of 8.8 (HIGH). In the Linux kernel, the following vulnerability has been resolved: drm/gpusvm: publish dpagemap early to avoid device mapping leak on error drm_gpusvm_get_pages() only stored the local dpagemap int...
How severe is CVE-2026-68240?
CVE-2026-68240 has been rated HIGH with a CVSS base score of 8.8/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2026-68240?
Check the references section above for vendor advisories and patch information. Review vendor security bulletins for remediation guidance.