{"id":"DEBIAN-CVE-2025-38355","details":"In the Linux kernel, the following vulnerability has been resolved:  drm/xe: Process deferred GGTT node removals on device unwind  While we are indirectly draining our dedicated workqueue ggtt-\u003ewq that we use to complete asynchronous removal of some GGTT nodes, this happends as part of the managed-drm unwinding (ggtt_fini_early), which could be later then manage-device unwinding, where we could already unmap our MMIO/GMS mapping (mmio_fini).  This was recently observed during unsuccessful VF initialization:   [ ] xe 0000:00:02.1: probe with driver xe failed with error -62  [ ] xe 0000:00:02.1: DEVRES REL ffff88811e747340 __xe_bo_unpin_map_no_vm (16 bytes)  [ ] xe 0000:00:02.1: DEVRES REL ffff88811e747540 __xe_bo_unpin_map_no_vm (16 bytes)  [ ] xe 0000:00:02.1: DEVRES REL ffff88811e747240 __xe_bo_unpin_map_no_vm (16 bytes)  [ ] xe 0000:00:02.1: DEVRES REL ffff88811e747040 tiles_fini (16 bytes)  [ ] xe 0000:00:02.1: DEVRES REL ffff88811e746840 mmio_fini (16 bytes)  [ ] xe 0000:00:02.1: DEVRES REL ffff88811e747f40 xe_bo_pinned_fini (16 bytes)  [ ] xe 0000:00:02.1: DEVRES REL ffff88811e746b40 devm_drm_dev_init_release (16 bytes)  [ ] xe 0000:00:02.1: [drm:drm_managed_release] drmres release begin  [ ] xe 0000:00:02.1: [drm:drm_managed_release] REL ffff88810ef81640 __fini_relay (8 bytes)  [ ] xe 0000:00:02.1: [drm:drm_managed_release] REL ffff88810ef80d40 guc_ct_fini (8 bytes)  [ ] xe 0000:00:02.1: [drm:drm_managed_release] REL ffff88810ef80040 __drmm_mutex_release (8 bytes)  [ ] xe 0000:00:02.1: [drm:drm_managed_release] REL ffff88810ef80140 ggtt_fini_early (8 bytes)  and this was leading to:   [ ] BUG: unable to handle page fault for address: ffffc900058162a0  [ ] #PF: supervisor write access in kernel mode  [ ] #PF: error_code(0x0002) - not-present page  [ ] Oops: Oops: 0002 [#1] SMP NOPTI  [ ] Tainted: [W]=WARN  [ ] Workqueue: xe-ggtt-wq ggtt_node_remove_work_func [xe]  [ ] RIP: 0010:xe_ggtt_set_pte+0x6d/0x350 [xe]  [ ] Call Trace:  [ ]  \u003cTASK\u003e  [ ]  xe_ggtt_clear+0xb0/0x270 [xe]  [ ]  ggtt_node_remove+0xbb/0x120 [xe]  [ ]  ggtt_node_remove_work_func+0x30/0x50 [xe]  [ ]  process_one_work+0x22b/0x6f0  [ ]  worker_thread+0x1e8/0x3d  Add managed-device action that will explicitly drain the workqueue with all pending node removals prior to releasing MMIO/GSM mapping.  (cherry picked from commit 89d2835c3680ab1938e22ad81b1c9f8c686bd391)","modified":"2026-08-27T23:05:29.744844290Z","published":"2025-07-25T13:15:24.240Z","upstream":["CVE-2025-38355"],"references":[{"type":"ADVISORY","url":"https://security-tracker.debian.org/tracker/CVE-2025-38355"}],"affected":[{"package":{"name":"linux","ecosystem":"Debian:13","purl":"pkg:deb/debian/linux?arch=source&distro=trixie"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"6.12.37-1"}]}],"ecosystem_specific":{"urgency":"not yet assigned"},"database_specific":{"source":"https://storage.googleapis.com/osv-test-debian-osv/debian-cve-osv/DEBIAN-CVE-2025-38355.json"}},{"package":{"name":"linux","ecosystem":"Debian:14","purl":"pkg:deb/debian/linux?arch=source&distro=forky"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"6.12.37-1"}]}],"ecosystem_specific":{"urgency":"not yet assigned"},"database_specific":{"source":"https://storage.googleapis.com/osv-test-debian-osv/debian-cve-osv/DEBIAN-CVE-2025-38355.json"}}],"schema_version":"1.9.0","severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H"}]}