{"api_version":"1","generated_at":"2026-09-17T20:26:20+00:00","cve":"CVE-2026-93180","urls":{"html":"https://cve.report/CVE-2026-93180","api":"https://cve.report/api/cve/CVE-2026-93180.json","docs":"https://cve.report/api","cve_org":"https://www.cve.org/CVERecord?id=CVE-2026-93180","nvd":"https://nvd.nist.gov/vuln/detail/CVE-2026-93180"},"summary":{"title":"drm/panthor: Fix NPD issue on partial unmap of an evicted BO","description":"In the Linux kernel, the following vulnerability has been resolved:\n\ndrm/panthor: Fix NPD issue on partial unmap of an evicted BO\n\nThis commit fixes the NULL pointer dereference issue that would have\nhappened on the split of GPU mapping due to partial unmap of an evicted\nBO. There is a logic to handle the partial unmap of huge pages when the\nGPU mapping is split. That logic was not being completely skipped for\nthe VMA of an evicted BO and that resulted in a NPD possibility for the\n'bo->backing.pages' pointer, which is set to NULL when pages of a\nBO are released on eviction.\n\nFollowing dump was seen when a partial unmap was exercised for an\nevicted BO.\nUnable to handle kernel paging request at virtual address 0000000000002000\nMem abort info:\n  ESR = 0x0000000096000004\n  EC = 0x25: DABT (current EL), IL = 32 bits\n  SET = 0, FnV = 0\n  EA = 0, S1PTW = 0\n  FSC = 0x04: level 0 translation fault\nData abort info:\n  ISV = 0, ISS = 0x00000004, ISS2 = 0x00000000\n  CM = 0, WnR = 0, TnD = 0, TagAccess = 0\n  GCS = 0, Overlay = 0, DirtyBit = 0, Xs = 0\nuser pgtable: 4k pages, 48-bit VAs, pgdp=00000008842e8000\n[0000000000002000] pgd=0000000000000000, p4d=0000000000000000\nInternal error: Oops: 0000000096000004 [#1]  SMP\n<snip>\npstate: 20000005 (nzCv daif -PAN -UAO -TCO -DIT -SSBS BTYPE=--)\npc : iova_mapped_as_huge_page+0x20/0x68 [panthor]\nlr : panthor_gpuva_sm_step_remap+0x39c/0x498 [panthor]\nsp : ffff800086193920\nx29: ffff800086193920 x28: ffff800086193a18 x27: ffff800086193b80\nx26: 0000000000400000 x25: 0000000000810000 x24: 0000000000400000\nx23: ffff000808af1800 x22: 0000000000a00000 x21: ffff800086193a00\nx20: ffff000806fd3f00 x19: 0000000000410000 x18: 00000000ffffffff\nx17: 0000000000000000 x16: 0000000000000000 x15: ffff800083ce2d83\nx14: 0000000000000000 x13: 3120646574636976 x12: 6520303030303138\nx11: 2d30303030313420 x10: ffff8000836e6c80 x9 : ffff80007bfc889c\nx8 : 3fffffffffffefff x7 : ffff8000836e6c80 x6 : 0000000000000000\nx5 : ffff00097ef19088 x4 : 0000000000000000 x3 : 0000000000000000\nx2 : 0000000000010000 x1 : 0000000000000400 x0 : 0000000000000000\nCall trace:\n iova_mapped_as_huge_page+0x20/0x68 [panthor] (P)\n op_remap_cb.isra.0+0x70/0xb0\n __drm_gpuvm_sm_unmap+0xf8/0x1c0\n drm_gpuvm_sm_unmap+0x40/0x60\n panthor_vm_exec_op+0xa0/0x168 [panthor]\n panthor_vm_bind_exec_sync_op+0x8c/0xb8 [panthor]\n panthor_ioctl_vm_bind+0xbc/0x170 [panthor]\n drm_ioctl_kernel+0xc0/0x140\n drm_ioctl+0x20c/0x500\n __arm64_sys_ioctl+0xb4/0x118\n invoke_syscall+0x5c/0x120\n el0_svc_common.constprop.0+0x48/0xf8\n do_el0_svc+0x28/0x40\n el0_svc+0x38/0x128\n el0t_64_sync_handler+0xa0/0xe8\n el0t_64_sync+0x198/0x1a0\nCode: 8b030021 cb020021 f940b800 d34cfc21 (f8617801)\n---[ end trace 0000000000000000 ]---\n\nv2: Fix indentation","state":"PUBLISHED","assigner":"Linux","published_at":"2026-09-17 17:18:13","updated_at":"2026-09-17 17:18:13"},"problem_types":[],"metrics":[],"references":[{"url":"https://git.kernel.org/stable/c/23d41b2e68765ad7095b1424f70c21c281f8a600","name":"https://git.kernel.org/stable/c/23d41b2e68765ad7095b1424f70c21c281f8a600","refsource":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","tags":[],"title":"","mime":"","httpstatus":"","archivestatus":"0"},{"url":"https://git.kernel.org/stable/c/5fb40edc7439b99d001988da63485ca51dbd3550","name":"https://git.kernel.org/stable/c/5fb40edc7439b99d001988da63485ca51dbd3550","refsource":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","tags":[],"title":"","mime":"","httpstatus":"","archivestatus":"0"},{"url":"https://www.cve.org/CVERecord?id=CVE-2026-93180","name":"CVE Program record","refsource":"CVE.ORG","tags":["canonical"]},{"url":"https://nvd.nist.gov/vuln/detail/CVE-2026-93180","name":"NVD vulnerability detail","refsource":"NVD","tags":["canonical","analysis"]}],"affected":[{"source":"CNA","vendor":"Linux","product":"Linux","version":"affected 8e7460eac786c72f48c4e04ce9be692b939428ce 23d41b2e68765ad7095b1424f70c21c281f8a600 git","platforms":[]},{"source":"CNA","vendor":"Linux","product":"Linux","version":"affected 8e7460eac786c72f48c4e04ce9be692b939428ce 5fb40edc7439b99d001988da63485ca51dbd3550 git","platforms":[]},{"source":"CNA","vendor":"Linux","product":"Linux","version":"affected 7.0","platforms":[]},{"source":"CNA","vendor":"Linux","product":"Linux","version":"unaffected 7.0 semver","platforms":[]},{"source":"CNA","vendor":"Linux","product":"Linux","version":"unaffected 7.2.6 7.2.* semver","platforms":[]},{"source":"CNA","vendor":"Linux","product":"Linux","version":"unaffected 7.3-rc1 * original_commit_for_fix","platforms":[]}],"timeline":[],"solutions":[],"workarounds":[],"exploits":[],"credits":[],"nvd_cpes":[],"vendor_comments":[],"enrichments":{"kev":null,"epss":null,"legacy_qids":[]},"source_records":{"cve_program":{"containers":{"cna":{"affected":[{"defaultStatus":"unaffected","product":"Linux","programFiles":["drivers/gpu/drm/panthor/panthor_mmu.c"],"repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","vendor":"Linux","versions":[{"lessThan":"23d41b2e68765ad7095b1424f70c21c281f8a600","status":"affected","version":"8e7460eac786c72f48c4e04ce9be692b939428ce","versionType":"git"},{"lessThan":"5fb40edc7439b99d001988da63485ca51dbd3550","status":"affected","version":"8e7460eac786c72f48c4e04ce9be692b939428ce","versionType":"git"}]},{"defaultStatus":"affected","product":"Linux","programFiles":["drivers/gpu/drm/panthor/panthor_mmu.c"],"repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","vendor":"Linux","versions":[{"status":"affected","version":"7.0"},{"lessThan":"7.0","status":"unaffected","version":"0","versionType":"semver"},{"lessThanOrEqual":"7.2.*","status":"unaffected","version":"7.2.6","versionType":"semver"},{"lessThanOrEqual":"*","status":"unaffected","version":"7.3-rc1","versionType":"original_commit_for_fix"}]}],"cpeApplicability":[{"nodes":[{"cpeMatch":[{"criteria":"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*","versionEndExcluding":"7.2.6","versionStartIncluding":"7.0","vulnerable":true},{"criteria":"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*","versionEndExcluding":"7.3-rc1","versionStartIncluding":"7.0","vulnerable":true}],"negate":false,"operator":"OR"}]}],"descriptions":[{"lang":"en","value":"In the Linux kernel, the following vulnerability has been resolved:\n\ndrm/panthor: Fix NPD issue on partial unmap of an evicted BO\n\nThis commit fixes the NULL pointer dereference issue that would have\nhappened on the split of GPU mapping due to partial unmap of an evicted\nBO. There is a logic to handle the partial unmap of huge pages when the\nGPU mapping is split. That logic was not being completely skipped for\nthe VMA of an evicted BO and that resulted in a NPD possibility for the\n'bo->backing.pages' pointer, which is set to NULL when pages of a\nBO are released on eviction.\n\nFollowing dump was seen when a partial unmap was exercised for an\nevicted BO.\nUnable to handle kernel paging request at virtual address 0000000000002000\nMem abort info:\n  ESR = 0x0000000096000004\n  EC = 0x25: DABT (current EL), IL = 32 bits\n  SET = 0, FnV = 0\n  EA = 0, S1PTW = 0\n  FSC = 0x04: level 0 translation fault\nData abort info:\n  ISV = 0, ISS = 0x00000004, ISS2 = 0x00000000\n  CM = 0, WnR = 0, TnD = 0, TagAccess = 0\n  GCS = 0, Overlay = 0, DirtyBit = 0, Xs = 0\nuser pgtable: 4k pages, 48-bit VAs, pgdp=00000008842e8000\n[0000000000002000] pgd=0000000000000000, p4d=0000000000000000\nInternal error: Oops: 0000000096000004 [#1]  SMP\n<snip>\npstate: 20000005 (nzCv daif -PAN -UAO -TCO -DIT -SSBS BTYPE=--)\npc : iova_mapped_as_huge_page+0x20/0x68 [panthor]\nlr : panthor_gpuva_sm_step_remap+0x39c/0x498 [panthor]\nsp : ffff800086193920\nx29: ffff800086193920 x28: ffff800086193a18 x27: ffff800086193b80\nx26: 0000000000400000 x25: 0000000000810000 x24: 0000000000400000\nx23: ffff000808af1800 x22: 0000000000a00000 x21: ffff800086193a00\nx20: ffff000806fd3f00 x19: 0000000000410000 x18: 00000000ffffffff\nx17: 0000000000000000 x16: 0000000000000000 x15: ffff800083ce2d83\nx14: 0000000000000000 x13: 3120646574636976 x12: 6520303030303138\nx11: 2d30303030313420 x10: ffff8000836e6c80 x9 : ffff80007bfc889c\nx8 : 3fffffffffffefff x7 : ffff8000836e6c80 x6 : 0000000000000000\nx5 : ffff00097ef19088 x4 : 0000000000000000 x3 : 0000000000000000\nx2 : 0000000000010000 x1 : 0000000000000400 x0 : 0000000000000000\nCall trace:\n iova_mapped_as_huge_page+0x20/0x68 [panthor] (P)\n op_remap_cb.isra.0+0x70/0xb0\n __drm_gpuvm_sm_unmap+0xf8/0x1c0\n drm_gpuvm_sm_unmap+0x40/0x60\n panthor_vm_exec_op+0xa0/0x168 [panthor]\n panthor_vm_bind_exec_sync_op+0x8c/0xb8 [panthor]\n panthor_ioctl_vm_bind+0xbc/0x170 [panthor]\n drm_ioctl_kernel+0xc0/0x140\n drm_ioctl+0x20c/0x500\n __arm64_sys_ioctl+0xb4/0x118\n invoke_syscall+0x5c/0x120\n el0_svc_common.constprop.0+0x48/0xf8\n do_el0_svc+0x28/0x40\n el0_svc+0x38/0x128\n el0t_64_sync_handler+0xa0/0xe8\n el0t_64_sync+0x198/0x1a0\nCode: 8b030021 cb020021 f940b800 d34cfc21 (f8617801)\n---[ end trace 0000000000000000 ]---\n\nv2: Fix indentation"}],"providerMetadata":{"dateUpdated":"2026-09-17T16:12:08.005Z","orgId":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","shortName":"Linux"},"references":[{"url":"https://git.kernel.org/stable/c/23d41b2e68765ad7095b1424f70c21c281f8a600"},{"url":"https://git.kernel.org/stable/c/5fb40edc7439b99d001988da63485ca51dbd3550"}],"title":"drm/panthor: Fix NPD issue on partial unmap of an evicted BO","x_generator":{"engine":"bippy-1.2.0"}}},"cveMetadata":{"assignerOrgId":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","assignerShortName":"Linux","cveId":"CVE-2026-93180","datePublished":"2026-09-17T16:12:08.005Z","dateReserved":"2026-09-17T16:02:15.091Z","dateUpdated":"2026-09-17T16:12:08.005Z","state":"PUBLISHED"},"dataType":"CVE_RECORD","dataVersion":"5.2"},"nvd":{"publishedDate":"2026-09-17 17:18:13","lastModifiedDate":"2026-09-17 17:18:13","problem_types":[],"metrics":[],"configurations":[]},"legacy_mitre":{"record":{"CveYear":"2026","CveId":"93180","Ordinal":"1","Title":"drm/panthor: Fix NPD issue on partial unmap of an evicted BO","CVE":"CVE-2026-93180","Year":"2026"},"notes":[{"CveYear":"2026","CveId":"93180","Ordinal":"1","NoteData":"In the Linux kernel, the following vulnerability has been resolved:\n\ndrm/panthor: Fix NPD issue on partial unmap of an evicted BO\n\nThis commit fixes the NULL pointer dereference issue that would have\nhappened on the split of GPU mapping due to partial unmap of an evicted\nBO. There is a logic to handle the partial unmap of huge pages when the\nGPU mapping is split. That logic was not being completely skipped for\nthe VMA of an evicted BO and that resulted in a NPD possibility for the\n'bo->backing.pages' pointer, which is set to NULL when pages of a\nBO are released on eviction.\n\nFollowing dump was seen when a partial unmap was exercised for an\nevicted BO.\nUnable to handle kernel paging request at virtual address 0000000000002000\nMem abort info:\n  ESR = 0x0000000096000004\n  EC = 0x25: DABT (current EL), IL = 32 bits\n  SET = 0, FnV = 0\n  EA = 0, S1PTW = 0\n  FSC = 0x04: level 0 translation fault\nData abort info:\n  ISV = 0, ISS = 0x00000004, ISS2 = 0x00000000\n  CM = 0, WnR = 0, TnD = 0, TagAccess = 0\n  GCS = 0, Overlay = 0, DirtyBit = 0, Xs = 0\nuser pgtable: 4k pages, 48-bit VAs, pgdp=00000008842e8000\n[0000000000002000] pgd=0000000000000000, p4d=0000000000000000\nInternal error: Oops: 0000000096000004 [#1]  SMP\n<snip>\npstate: 20000005 (nzCv daif -PAN -UAO -TCO -DIT -SSBS BTYPE=--)\npc : iova_mapped_as_huge_page+0x20/0x68 [panthor]\nlr : panthor_gpuva_sm_step_remap+0x39c/0x498 [panthor]\nsp : ffff800086193920\nx29: ffff800086193920 x28: ffff800086193a18 x27: ffff800086193b80\nx26: 0000000000400000 x25: 0000000000810000 x24: 0000000000400000\nx23: ffff000808af1800 x22: 0000000000a00000 x21: ffff800086193a00\nx20: ffff000806fd3f00 x19: 0000000000410000 x18: 00000000ffffffff\nx17: 0000000000000000 x16: 0000000000000000 x15: ffff800083ce2d83\nx14: 0000000000000000 x13: 3120646574636976 x12: 6520303030303138\nx11: 2d30303030313420 x10: ffff8000836e6c80 x9 : ffff80007bfc889c\nx8 : 3fffffffffffefff x7 : ffff8000836e6c80 x6 : 0000000000000000\nx5 : ffff00097ef19088 x4 : 0000000000000000 x3 : 0000000000000000\nx2 : 0000000000010000 x1 : 0000000000000400 x0 : 0000000000000000\nCall trace:\n iova_mapped_as_huge_page+0x20/0x68 [panthor] (P)\n op_remap_cb.isra.0+0x70/0xb0\n __drm_gpuvm_sm_unmap+0xf8/0x1c0\n drm_gpuvm_sm_unmap+0x40/0x60\n panthor_vm_exec_op+0xa0/0x168 [panthor]\n panthor_vm_bind_exec_sync_op+0x8c/0xb8 [panthor]\n panthor_ioctl_vm_bind+0xbc/0x170 [panthor]\n drm_ioctl_kernel+0xc0/0x140\n drm_ioctl+0x20c/0x500\n __arm64_sys_ioctl+0xb4/0x118\n invoke_syscall+0x5c/0x120\n el0_svc_common.constprop.0+0x48/0xf8\n do_el0_svc+0x28/0x40\n el0_svc+0x38/0x128\n el0t_64_sync_handler+0xa0/0xe8\n el0t_64_sync+0x198/0x1a0\nCode: 8b030021 cb020021 f940b800 d34cfc21 (f8617801)\n---[ end trace 0000000000000000 ]---\n\nv2: Fix indentation","Type":"Description","Title":"drm/panthor: Fix NPD issue on partial unmap of an evicted BO"}]}}}