drm/xe/migrate: don't overflow max copy size
Published Sep 11, 2025
5.5
MEDIUMCVSS 3.1
EPSS 0.14%
Description
With non-page aligned copy, we need to use 4 byte aligned pitch, however the size itself might still be close to our maximum of ~8M, and so the dimensions of the copy can easily exceed the S16_MAX limit of the copy command leading to the following assert:
xe 0000:03:00.0: [drm] Assertion `size / pitch <= ((s16)(((u16)~0U) >> 1))` failed! platform: BATTLEMAGE subplatform: 1 graphics: Xe2_HPG 20.01 step A0 media: Xe2_HPM 13.01 step A1 tile: 0 VRAM 10.0 GiB GT: 0 type 1
WARNING: CPU: 23 PID: 10605 at drivers/gpu/drm/xe/xe_migrate.c:673 emit_copy+0x4b5/0x4e0 [xe]
To fix this account for the pitch when calculating the number of current bytes to copy.
(cherry picked from commit 8c2d61e0e916e077fda7e7b8e67f25ffe0f361fc)
Affected products
-
- Version StatusaffectedConstraints
- Version StatusaffectedConstraints
- Version
-
- Version 6.16StatusaffectedConstraints-
- Version 0StatusunaffectedConstraints<6.16
- Version 6.16.2StatusunaffectedConstraints<=6.16.*
- Version 6.17StatusunaffectedConstraints<=*
- Version
Default status is the baseline for the product, each version can override it (e.g. patched versions marked unaffected).
- ≥ 6.16 · < 6.16.2
- 6.17
No data.
Red Hat Enterprise Linux 10
kernel
Not affected
Red Hat Enterprise Linux 6
kernel
Not affected
Red Hat Enterprise Linux 7
kernel
Not affected
Red Hat Enterprise Linux 7
kernel-rt
Not affected
Red Hat Enterprise Linux 8
kernel
Not affected
Red Hat Enterprise Linux 8
kernel-rt
Not affected
Red Hat Enterprise Linux 9
kernel
Not affected
Red Hat Enterprise Linux 9
kernel-rt
Not affected
| Product | Package | State | Advisory |
|---|---|---|---|
| Red Hat Enterprise Linux 10 | kernel | Not affected | n/a |
| Red Hat Enterprise Linux 6 | kernel | Not affected | n/a |
| Red Hat Enterprise Linux 7 | kernel | Not affected | n/a |
| Red Hat Enterprise Linux 7 | kernel-rt | Not affected | n/a |
| Red Hat Enterprise Linux 8 | kernel | Not affected | n/a |
| Red Hat Enterprise Linux 8 | kernel-rt | Not affected | n/a |
| Red Hat Enterprise Linux 9 | kernel | Not affected | n/a |
| Red Hat Enterprise Linux 9 | kernel-rt | Not affected | n/a |
No package ranges for this CVE.
Remediation
No remediation recorded yet.
No CWE recorded.
References (8)
- https://access.redhat.com/security/cve/CVE-2025-39741 Vendor Advisory
- https://bugzilla.redhat.com/show_bug.cgi?id=2394631 Issue Tracking
- https://euvd.enisa.europa.eu/vulnerability/EUVD-2025-28970 Advisory
- https://git.kernel.org/stable/c/4126cb327a2e3273c81fcef1c594c5b7b645c44c Patch
- https://git.kernel.org/stable/c/7257cc6644d540130a46a61531a07a0517cace89 Patch
- https://lore.kernel.org/linux-cve-announce/2025091138-CVE-2025-39741-8730@gregkh/T
- https://nvd.nist.gov/vuln/detail/CVE-2025-39741
- https://www.cve.org/CVERecord?id=CVE-2025-39741
Change history (0)
No recorded changes yet.