{"apiVersion":"1.0","identifier":"CVE-2026-72358","description":"In the Linux kernel, the following vulnerability has been resolved: drm/xe/pt: prevent invalid cursor access for purged BOs During a page table walk for binding, xe_pt_stage_bind() explicitly skips initializing the xe_res_cursor for purged BOs, treating them similarly to NULL VMAs by only setting the cursor size. However, xe_pt_hugepte_possible() and xe_pt_scan_64K() did not check if the BO was purged before attempting to walk the cursor using xe_res_dma() and xe_res_next(). Because the cursor was left uninitialized for purged BOs, this falls through and triggers warnings like: WARNING: drivers/gpu/drm/xe/xe_res_cursor.h:274 at xe_res_next Fix this by explicitly checking if the BO is purged in both xe_pt_hugepte_possible() and xe_pt_scan_64K(), returning early just as we do for NULL VMAs, avoiding the invalid cursor accesses entirely. As a precaution, also zero-initialize the cursor in xe_pt_stage_bind() to ensure we don-t pass garbage data into the page table walkers if we ever hit a similar edge case in the future. (cherry picked from commit 4c7b9c6ece32440e5a435a92076d049450cd2d2e)","publishedAt":"2026-08-15T06:22:09","lastModifiedAt":"2026-08-17T06:18:39","sourceUrl":"https://nvd.nist.gov/vuln/detail/CVE-2026-72358","cvssScore":7.8,"cvssVector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H","epssProbability":0.00165,"riskScore":0.79,"affectedProduct":"Linux kernel","affectedVersions":"unknown","vulnerabilityType":"Kernel","operatingSystems":[],"links":{"self":"https://www.redsauce.net/api/cves/CVE-2026-72358","webPages":{"es":"https://www.redsauce.net/es/cves/CVE-2026-72358","en":"https://www.redsauce.net/en/cves/CVE-2026-72358","fr":"https://www.redsauce.net/fr/cves/CVE-2026-72358","pt":"https://www.redsauce.net/pt/cves/CVE-2026-72358","de":"https://www.redsauce.net/de/cves/CVE-2026-72358","sk":"https://www.redsauce.net/sk/cves/CVE-2026-72358","el":"https://www.redsauce.net/el/cves/CVE-2026-72358"},"source":"https://nvd.nist.gov/vuln/detail/CVE-2026-72358"}}