CVE-2026-64590
Received Received - Intake

DMA-API Debug Warning in Linux Kernel udmabuf

Vulnerability report for CVE-2026-64590, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-08-06

Last updated on: 2026-08-06

Assigner: kernel.org

Description

In the Linux kernel, the following vulnerability has been resolved: dma-buf/udmabuf: skip redundant cpu sync to fix cacheline EEXIST warning When CONFIG_DMA_API_DEBUG_SG is enabled, importing a udmabuf into a DRM driver (e.g. amdgpu for video playback in GNOME Videos / Showtime) triggers a spurious warning: DMA-API: amdgpu 0000:03:00.0: cacheline tracking EEXIST, \ overlapping mappings aren't supported WARNING: kernel/dma/debug.c:619 at add_dma_entry+0x473/0x5f0 The call chain is: amdgpu_cs_ioctl -> amdgpu_ttm_backend_bind -> dma_buf_map_attachment -> [udmabuf] map_udmabuf -> get_sg_table -> dma_map_sgtable(dev, sg, direction, 0) // attrs=0 -> debug_dma_map_sg -> add_dma_entry -> EEXIST This happens because udmabuf builds a per-page scatter-gather list via sg_set_folio(). When begin_cpu_udmabuf() has already created an sg table mapped for the misc device, and an importer such as amdgpu maps the same pages for its own device via map_udmabuf(), the DMA debug infrastructure sees two active mappings whose physical addresses share cacheline boundaries and warns about the overlap. The DMA_ATTR_SKIP_CPU_SYNC flag suppresses this check in add_dma_entry() because it signals that no CPU cache maintenance is performed at map/unmap time, making the cacheline overlap harmless. All other major dma-buf exporters already pass this flag: - drm_gem_map_dma_buf() passes DMA_ATTR_SKIP_CPU_SYNC - amdgpu_dma_buf_map() passes DMA_ATTR_SKIP_CPU_SYNC The CPU sync at map/unmap time is also redundant for udmabuf: begin_cpu_udmabuf() and end_cpu_udmabuf() already perform explicit cache synchronization via dma_sync_sgtable_for_cpu/device() when CPU access is requested through the dma-buf interface. Pass DMA_ATTR_SKIP_CPU_SYNC to dma_map_sgtable() and dma_unmap_sgtable() in udmabuf to suppress the spurious warning and skip the redundant sync.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-08-06
Last Modified
2026-08-06
Generated
2026-08-06
AI Q&A
2026-08-06
EPSS Evaluated
N/A
NVD
EUVD

Affected Vendors & Products

Showing 1 associated CPE
Vendor Product Version / Range
amdgpu amdgpu *

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-UNKNOWN

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

This is a Linux kernel vulnerability in the dma-buf/udmabuf subsystem. When a specific debug option is enabled, importing a udmabuf into a DRM driver like amdgpu triggers a false warning about overlapping memory mappings. The issue occurs because udmabuf creates scatter-gather lists per page, and when another driver maps the same pages, the DMA debug system incorrectly flags it as an overlap. The fix involves passing a flag to skip unnecessary CPU synchronization during mapping operations.

Detection Guidance

This vulnerability is specific to the Linux kernel's dma-buf/udmabuf implementation and does not have a direct network detection method. Detection involves checking kernel logs for the EEXIST warning related to cacheline tracking. Use commands like dmesg | grep EEXIST or journalctl -k | grep EEXIST to search for the warning.

Impact Analysis

This vulnerability causes spurious warning messages in kernel logs when using video playback applications like GNOME Videos or Showtime with certain hardware. While it doesn't directly affect functionality or security, the warnings may indicate potential issues with memory mapping that could lead to performance problems or system instability in some configurations.

Mitigation Strategies

Apply the kernel patch that adds DMA_ATTR_SKIP_CPU_SYNC to dma_map_sgtable and dma_unmap_sgtable in udmabuf. Update your Linux kernel to a version containing this fix. No immediate user-level mitigation is required beyond updating the kernel.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-64590. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart