Information Exposure Through Caching Affecting rv package, versions *


Severity

Recommended
0.0
high
0
10

Based on Red Hat Enterprise Linux security rating.

Threat Intelligence

EPSS
0.02% (7th percentile)

Do your applications use this vulnerable package?

In a few clicks we can analyze your entire application and see what components are vulnerable in your application, and suggest you quick fixes.

Test your applications
  • Snyk IDSNYK-RHEL10-RV-17243971
  • published9 Jun 2026
  • disclosed8 Jun 2026

Introduced: 8 Jun 2026

NewCVE-2026-46309  (opens in a new tab)
CWE-524  (opens in a new tab)

How to fix?

There is no fixed version for RHEL:10 rv.

NVD Description

Note: Versions mentioned in the description apply only to the upstream rv package and not the rv package as distributed by RHEL. See How to fix? for RHEL:10 relevant fixed versions and status.

In the Linux kernel, the following vulnerability has been resolved:

drm/xe/uapi: Reject coh_none PAT index for CPU cached memory in madvise

Add validation in xe_vm_madvise_ioctl() to reject PAT indices with XE_COH_NONE coherency mode when applied to CPU cached memory.

Using coh_none with CPU cached buffers is a security issue. When the kernel clears pages before reallocation, the clear operation stays in CPU cache (dirty). GPU with coh_none can bypass CPU caches and read stale sensitive data directly from DRAM, potentially leaking data from previously freed pages of other processes.

This aligns with the existing validation in vm_bind path (xe_vm_bind_ioctl_validate_bo).

v2(Matthew brost)

  • Add fixes
  • Move one debug print to better place

v3(Matthew Auld)

  • Should be drm/xe/uapi
  • More Cc

v4(Shuicheng Lin)

  • Fix kmem leak issues by the way

v5

  • Remove kmem leak because it has been merged by another patch

v6

  • Remove the fix which is not related to current fix

v7

  • No change

v8

  • Rebase

v9

  • Limit the restrictions to iGPU

v10

  • No change

(cherry picked from commit 016ccdb674b8c899940b3944952c96a6a490d10a)

CVSS Base Scores

version 3.1