--- /dev/null
+From stable+bounces-294461-greg=kroah.com@vger.kernel.org Sun Aug 2 04:33:28 2026
+From: Sasha Levin <sashal@kernel.org>
+Date: Sat, 1 Aug 2026 22:33:17 -0400
+Subject: drm/i915/hdcp: check streams[] bounds before overflow
+To: stable@vger.kernel.org
+Cc: Jani Nikula <jani.nikula@intel.com>, Martin Hodo <martin.hodo@intel.com>, Anshuman Gupta <anshuman.gupta@intel.com>, Suraj Kandpal <suraj.kandpal@intel.com>, Joonas Lahtinen <joonas.lahtinen@linux.intel.com>, Sasha Levin <sashal@kernel.org>
+Message-ID: <20260802023317.1298318-3-sashal@kernel.org>
+
+From: Jani Nikula <jani.nikula@intel.com>
+
+[ Upstream commit bbb15a6b042d02e5508a02b4847e02d2579ee7bc ]
+
+The data->streams[] overflow check is done after the buffer overflow has
+already happened. Move the overflow check before the write.
+
+Side note, emitting a warning splat with a backtrace might be overkill
+here, but prefer not changing the behaviour other than not doing the
+overrun.
+
+Discovered using AI-assisted static analysis confirmed by Intel Product
+Security.
+
+Reported-by: Martin Hodo <martin.hodo@intel.com>
+Fixes: e03187e12cae ("drm/i915/hdcp: MST streams support in hdcp port_data")
+Cc: stable@vger.kernel.org # v5.12+
+Cc: Anshuman Gupta <anshuman.gupta@intel.com>
+Cc: Suraj Kandpal <suraj.kandpal@intel.com>
+Reviewed-by: Suraj Kandpal <suraj.kandpal@intel.com>
+Link: https://patch.msgid.link/20260625170304.1104723-1-jani.nikula@intel.com
+Signed-off-by: Jani Nikula <jani.nikula@intel.com>
+(cherry picked from commit 9284ab3b6e776c315883ac2611283d263c9460fd)
+Signed-off-by: Joonas Lahtinen <joonas.lahtinen@linux.intel.com>
+Signed-off-by: Sasha Levin <sashal@kernel.org>
+Signed-off-by: Greg Kroah-Hartman <gregkh@linuxfoundation.org>
+---
+ drivers/gpu/drm/i915/display/intel_hdcp.c | 5 ++++-
+ 1 file changed, 4 insertions(+), 1 deletion(-)
+
+--- a/drivers/gpu/drm/i915/display/intel_hdcp.c
++++ b/drivers/gpu/drm/i915/display/intel_hdcp.c
+@@ -129,6 +129,9 @@ intel_hdcp_required_content_stream(struc
+ if (!new_conn_state || !new_conn_state->crtc)
+ continue;
+
++ if (drm_WARN_ON(display->drm, data->k >= INTEL_NUM_PIPES(display)))
++ return -EINVAL;
++
+ data->streams[data->k].stream_id =
+ intel_conn_to_vcpi(state, connector);
+ data->k++;
+@@ -139,7 +142,7 @@ intel_hdcp_required_content_stream(struc
+ }
+ drm_connector_list_iter_end(&conn_iter);
+
+- if (drm_WARN_ON(display->drm, data->k > INTEL_NUM_PIPES(display) || data->k == 0))
++ if (drm_WARN_ON(display->drm, !data->k))
+ return -EINVAL;
+
+ /*
--- /dev/null
+From stable+bounces-294460-greg=kroah.com@vger.kernel.org Sun Aug 2 04:33:25 2026
+From: Sasha Levin <sashal@kernel.org>
+Date: Sat, 1 Aug 2026 22:33:16 -0400
+Subject: drm/i915/hdcp: Skip inactive MST connectors when building stream list
+To: stable@vger.kernel.org
+Cc: Suraj Kandpal <suraj.kandpal@intel.com>, Santhosh Reddy Guddati <santhosh.reddy.guddati@intel.com>, Sasha Levin <sashal@kernel.org>
+Message-ID: <20260802023317.1298318-2-sashal@kernel.org>
+
+From: Suraj Kandpal <suraj.kandpal@intel.com>
+
+[ Upstream commit 0161e2c2016337a2f22ef79dff0aee43c0841bce ]
+
+intel_hdcp_required_content_stream() walks every connector on the
+digital port to populate hdcp_port_data->streams[]. The only filter is
+connector_status_disconnected, which reflects physical presence on the
+MST topology, not whether the connector currently drives a stream.
+On a multi-sink MST setup where only a subset of sinks are modeset,
+the loop can pick a sibling MST connector that is connected but has
+no active CRTC / VC payload. intel_conn_to_vcpi() then logs "MST
+Payload not present" and returns 0, and the bogus StreamID=0 is
+written to the repeater in RepeaterAuth_Stream_Manage (DPCD 0x693F0).
+Authentication completes, but the repeater shortly raises
+LINK_INTEGRITY_FAILURE (RxStatus 0x69493 bit4) because the StreamID
+does not match any stream on its input. The HDCP check work then
+tears the link down, the Content Protection property drops back to
+DESIRED, and userspace observes a spurious HDCP enable failure.
+Filter the connector iteration to only those with a CRTC assigned in
+the new atomic state, so intel_conn_to_vcpi() is called for the
+connector actually being enabled and reads its real VCPI from the MST
+topology state.
+
+Signed-off-by: Suraj Kandpal <suraj.kandpal@intel.com>
+Reviewed-by: Santhosh Reddy Guddati <santhosh.reddy.guddati@intel.com>
+Link: https://patch.msgid.link/20260505094022.4064256-1-suraj.kandpal@intel.com
+Stable-dep-of: bbb15a6b042d ("drm/i915/hdcp: check streams[] bounds before overflow")
+Signed-off-by: Sasha Levin <sashal@kernel.org>
+Signed-off-by: Greg Kroah-Hartman <gregkh@linuxfoundation.org>
+---
+ drivers/gpu/drm/i915/display/intel_hdcp.c | 6 ++++++
+ 1 file changed, 6 insertions(+)
+
+--- a/drivers/gpu/drm/i915/display/intel_hdcp.c
++++ b/drivers/gpu/drm/i915/display/intel_hdcp.c
+@@ -97,6 +97,7 @@ intel_hdcp_required_content_stream(struc
+ {
+ struct intel_display *display = to_intel_display(state);
+ struct drm_connector_list_iter conn_iter;
++ struct drm_connector_state *new_conn_state;
+ struct intel_digital_port *conn_dig_port;
+ struct intel_connector *connector;
+ struct hdcp_port_data *data = &dig_port->hdcp_port_data;
+@@ -123,6 +124,11 @@ intel_hdcp_required_content_stream(struc
+ if (conn_dig_port != dig_port)
+ continue;
+
++ new_conn_state = drm_atomic_get_new_connector_state(&state->base,
++ &connector->base);
++ if (!new_conn_state || !new_conn_state->crtc)
++ continue;
++
+ data->streams[data->k].stream_id =
+ intel_conn_to_vcpi(state, connector);
+ data->k++;
--- /dev/null
+From stable+bounces-294797-greg=kroah.com@vger.kernel.org Mon Aug 3 18:24:14 2026
+From: Sasha Levin <sashal@kernel.org>
+Date: Mon, 3 Aug 2026 11:30:42 -0400
+Subject: drm/xe/pt: Reset current_op in xe_pt_update_ops_init()
+To: stable@vger.kernel.org
+Cc: "Zongyao Bai" <zongyao.bai@intel.com>, "Matthew Auld" <matthew.auld@intel.com>, "Matthew Brost" <matthew.brost@intel.com>, "Thomas Hellström" <thomas.hellstrom@linux.intel.com>, "Sasha Levin" <sashal@kernel.org>
+Message-ID: <20260803153043.878690-2-sashal@kernel.org>
+
+From: Zongyao Bai <zongyao.bai@intel.com>
+
+[ Upstream commit 6384271ac1ac0099198d15df79212a19ebdb929d ]
+
+xe_pt_update_ops_init() fails to reset current_op to 0. On the
+vm_bind path, ops_execute() calls xe_pt_update_ops_prepare() inside
+the xe_validation_guard() / drm_exec_until_all_locked() loop. When
+that loop retries due to lock contention or OOM eviction
+(drm_exec_retry_on_contention() / xe_validation_retry_on_oom()),
+xe_pt_update_ops_prepare() runs again on the same vops, and each
+call to bind_op_prepare() increments current_op without resetting it.
+
+After N retries current_op exceeds the array size allocated by
+xe_vma_ops_alloc(), causing an out-of-bounds write into
+SLUB-poisoned memory and a subsequent UAF crash in
+xe_migrate_update_pgtables_cpu() when reading the corrupted pt_op->bind.
+
+Also reset needs_svm_lock and needs_invalidation which are derived in
+the same prepare pass and would otherwise cause wrong migrate ops
+selection and redundant TLB invalidation on retry.
+
+Fix this by resetting current_op, needs_svm_lock and needs_invalidation
+in xe_pt_update_ops_init().
+
+v2 (Matt):
+ - Add details in commit message.
+ - Add Fixes tag and Cc to stable@vger.kernel.org
+
+Fixes: e8babb280b5e ("drm/xe: Convert multiple bind ops into single job")
+Suggested-by: Matthew Auld <matthew.auld@intel.com>
+Cc: stable@vger.kernel.org
+Assisted-by: GitHub-Copilot:claude-sonnet-4.6
+Signed-off-by: Zongyao Bai <zongyao.bai@intel.com>
+Reviewed-by: Matthew Brost <matthew.brost@intel.com>
+Signed-off-by: Matthew Brost <matthew.brost@intel.com>
+Link: https://patch.msgid.link/20260714232433.2737533-1-zongyao.bai@intel.com
+(cherry picked from commit 046045543e530605c441063535e7dca0075369a6)
+Signed-off-by: Thomas Hellström <thomas.hellstrom@linux.intel.com>
+Signed-off-by: Sasha Levin <sashal@kernel.org>
+Signed-off-by: Greg Kroah-Hartman <gregkh@linuxfoundation.org>
+---
+ drivers/gpu/drm/xe/xe_pt.c | 3 +++
+ 1 file changed, 3 insertions(+)
+
+--- a/drivers/gpu/drm/xe/xe_pt.c
++++ b/drivers/gpu/drm/xe/xe_pt.c
+@@ -1833,8 +1833,11 @@ static void
+ xe_pt_update_ops_init(struct xe_vm_pgtable_update_ops *pt_update_ops)
+ {
+ init_llist_head(&pt_update_ops->deferred);
++ pt_update_ops->current_op = 0;
+ pt_update_ops->start = ~0x0ull;
+ pt_update_ops->last = 0x0ull;
++ pt_update_ops->needs_userptr_lock = false;
++ pt_update_ops->needs_invalidation = false;
+ }
+
+ /**
--- /dev/null
+From stable+bounces-294796-greg=kroah.com@vger.kernel.org Mon Aug 3 19:00:29 2026
+From: Sasha Levin <sashal@kernel.org>
+Date: Mon, 3 Aug 2026 11:30:41 -0400
+Subject: drm/xe: Stub out new pagefault layer
+To: stable@vger.kernel.org
+Cc: Matthew Brost <matthew.brost@intel.com>, Lucas De Marchi <lucas.demarchi@intel.com>, Francois Dugast <francois.dugast@intel.com>, Sasha Levin <sashal@kernel.org>
+Message-ID: <20260803153043.878690-1-sashal@kernel.org>
+
+From: Matthew Brost <matthew.brost@intel.com>
+
+[ Upstream commit 620a09fb0bddf387f418663478b48ca4ba62b6d6 ]
+
+Stub out the new page fault layer and add kernel documentation. This is
+intended as a replacement for the GT page fault layer, enabling multiple
+producers to hook into a shared page fault consumer interface.
+
+v2:
+ - Fix kernel doc typo (checkpatch)
+ - Remove comment around GT (Stuart)
+ - Add explaination around reclaim (Francois)
+ - Add comment around u8 vs enum (Francois)
+ - Include engine instance (Stuart)
+v3:
+ - Fix XE_PAGEFAULT_TYPE_ATOMIC_ACCESS_VIOLATION kernel doc (Stuart)
+
+Signed-off-by: Matthew Brost <matthew.brost@intel.com>
+Reviewed-by: Lucas De Marchi <lucas.demarchi@intel.com>
+Tested-by: Francois Dugast <francois.dugast@intel.com>
+Link: https://patch.msgid.link/20251031165416.2871503-2-matthew.brost@intel.com
+Stable-dep-of: 6384271ac1ac ("drm/xe/pt: Reset current_op in xe_pt_update_ops_init()")
+Signed-off-by: Sasha Levin <sashal@kernel.org>
+Signed-off-by: Greg Kroah-Hartman <gregkh@linuxfoundation.org>
+---
+ drivers/gpu/drm/xe/Makefile | 1
+ drivers/gpu/drm/xe/xe_pagefault.c | 65 +++++++++++++++
+ drivers/gpu/drm/xe/xe_pagefault.h | 19 ++++
+ drivers/gpu/drm/xe/xe_pagefault_types.h | 136 ++++++++++++++++++++++++++++++++
+ 4 files changed, 221 insertions(+)
+ create mode 100644 drivers/gpu/drm/xe/xe_pagefault.c
+ create mode 100644 drivers/gpu/drm/xe/xe_pagefault.h
+ create mode 100644 drivers/gpu/drm/xe/xe_pagefault_types.h
+
+--- a/drivers/gpu/drm/xe/Makefile
++++ b/drivers/gpu/drm/xe/Makefile
+@@ -78,6 +78,7 @@ xe-y += xe_bb.o \
+ xe_module.o \
+ xe_oa.o \
+ xe_observation.o \
++ xe_pagefault.o \
+ xe_pat.o \
+ xe_pci.o \
+ xe_pcode.o \
+--- /dev/null
++++ b/drivers/gpu/drm/xe/xe_pagefault.c
+@@ -0,0 +1,65 @@
++// SPDX-License-Identifier: MIT
++/*
++ * Copyright © 2025 Intel Corporation
++ */
++
++#include "xe_pagefault.h"
++#include "xe_pagefault_types.h"
++
++/**
++ * DOC: Xe page faults
++ *
++ * Xe page faults are handled in two layers. The producer layer interacts with
++ * hardware or firmware to receive and parse faults into struct xe_pagefault,
++ * then forwards them to the consumer. The consumer layer services the faults
++ * (e.g., memory migration, page table updates) and acknowledges the result back
++ * to the producer, which then forwards the results to the hardware or firmware.
++ * The consumer uses a page fault queue sized to absorb all potential faults and
++ * a multi-threaded worker to process them. Multiple producers are supported,
++ * with a single shared consumer.
++ *
++ * xe_pagefault.c implements the consumer layer.
++ */
++
++/**
++ * xe_pagefault_init() - Page fault init
++ * @xe: xe device instance
++ *
++ * Initialize Xe page fault state. Must be done after reading fuses.
++ *
++ * Return: 0 on Success, errno on failure
++ */
++int xe_pagefault_init(struct xe_device *xe)
++{
++ /* TODO - implement */
++ return 0;
++}
++
++/**
++ * xe_pagefault_reset() - Page fault reset for a GT
++ * @xe: xe device instance
++ * @gt: GT being reset
++ *
++ * Reset the Xe page fault state for a GT; that is, squash any pending faults on
++ * the GT.
++ */
++void xe_pagefault_reset(struct xe_device *xe, struct xe_gt *gt)
++{
++ /* TODO - implement */
++}
++
++/**
++ * xe_pagefault_handler() - Page fault handler
++ * @xe: xe device instance
++ * @pf: Page fault
++ *
++ * Sink the page fault to a queue (i.e., a memory buffer) and queue a worker to
++ * service it. Safe to be called from IRQ or process context. Reclaim safe.
++ *
++ * Return: 0 on success, errno on failure
++ */
++int xe_pagefault_handler(struct xe_device *xe, struct xe_pagefault *pf)
++{
++ /* TODO - implement */
++ return 0;
++}
+--- /dev/null
++++ b/drivers/gpu/drm/xe/xe_pagefault.h
+@@ -0,0 +1,19 @@
++/* SPDX-License-Identifier: MIT */
++/*
++ * Copyright © 2025 Intel Corporation
++ */
++
++#ifndef _XE_PAGEFAULT_H_
++#define _XE_PAGEFAULT_H_
++
++struct xe_device;
++struct xe_gt;
++struct xe_pagefault;
++
++int xe_pagefault_init(struct xe_device *xe);
++
++void xe_pagefault_reset(struct xe_device *xe, struct xe_gt *gt);
++
++int xe_pagefault_handler(struct xe_device *xe, struct xe_pagefault *pf);
++
++#endif
+--- /dev/null
++++ b/drivers/gpu/drm/xe/xe_pagefault_types.h
+@@ -0,0 +1,136 @@
++/* SPDX-License-Identifier: MIT */
++/*
++ * Copyright © 2025 Intel Corporation
++ */
++
++#ifndef _XE_PAGEFAULT_TYPES_H_
++#define _XE_PAGEFAULT_TYPES_H_
++
++#include <linux/workqueue.h>
++
++struct xe_gt;
++struct xe_pagefault;
++
++/** enum xe_pagefault_access_type - Xe page fault access type */
++enum xe_pagefault_access_type {
++ /** @XE_PAGEFAULT_ACCESS_TYPE_READ: Read access type */
++ XE_PAGEFAULT_ACCESS_TYPE_READ = 0,
++ /** @XE_PAGEFAULT_ACCESS_TYPE_WRITE: Write access type */
++ XE_PAGEFAULT_ACCESS_TYPE_WRITE = 1,
++ /** @XE_PAGEFAULT_ACCESS_TYPE_ATOMIC: Atomic access type */
++ XE_PAGEFAULT_ACCESS_TYPE_ATOMIC = 2,
++};
++
++/** enum xe_pagefault_type - Xe page fault type */
++enum xe_pagefault_type {
++ /** @XE_PAGEFAULT_TYPE_NOT_PRESENT: Not present */
++ XE_PAGEFAULT_TYPE_NOT_PRESENT = 0,
++ /** @XE_PAGEFAULT_TYPE_WRITE_ACCESS_VIOLATION: Write access violation */
++ XE_PAGEFAULT_TYPE_WRITE_ACCESS_VIOLATION = 1,
++ /** @XE_PAGEFAULT_TYPE_ATOMIC_ACCESS_VIOLATION: Atomic access violation */
++ XE_PAGEFAULT_TYPE_ATOMIC_ACCESS_VIOLATION = 2,
++};
++
++/** struct xe_pagefault_ops - Xe pagefault ops (producer) */
++struct xe_pagefault_ops {
++ /**
++ * @ack_fault: Ack fault
++ * @pf: Page fault
++ * @err: Error state of fault
++ *
++ * Page fault producer receives acknowledgment from the consumer and
++ * sends the result to the HW/FW interface.
++ */
++ void (*ack_fault)(struct xe_pagefault *pf, int err);
++};
++
++/**
++ * struct xe_pagefault - Xe page fault
++ *
++ * Generic page fault structure for communication between producer and consumer.
++ * Carefully sized to be 64 bytes. Upon a device page fault, the producer
++ * populates this structure, and the consumer copies it into the page-fault
++ * queue for deferred handling.
++ */
++struct xe_pagefault {
++ /**
++ * @gt: GT of fault
++ */
++ struct xe_gt *gt;
++ /**
++ * @consumer: State for the software handling the fault. Populated by
++ * the producer and may be modified by the consumer to communicate
++ * information back to the producer upon fault acknowledgment.
++ */
++ struct {
++ /** @consumer.page_addr: address of page fault */
++ u64 page_addr;
++ /** @consumer.asid: address space ID */
++ u32 asid;
++ /**
++ * @consumer.access_type: access type, u8 rather than enum to
++ * keep size compact
++ */
++ u8 access_type;
++ /**
++ * @consumer.fault_type: fault type, u8 rather than enum to
++ * keep size compact
++ */
++ u8 fault_type;
++#define XE_PAGEFAULT_LEVEL_NACK 0xff /* Producer indicates nack fault */
++ /** @consumer.fault_level: fault level */
++ u8 fault_level;
++ /** @consumer.engine_class: engine class */
++ u8 engine_class;
++ /** @consumer.engine_instance: engine instance */
++ u8 engine_instance;
++ /** consumer.reserved: reserved bits for future expansion */
++ u8 reserved[7];
++ } consumer;
++ /**
++ * @producer: State for the producer (i.e., HW/FW interface). Populated
++ * by the producer and should not be modified—or even inspected—by the
++ * consumer, except for calling operations.
++ */
++ struct {
++ /** @producer.private: private pointer */
++ void *private;
++ /** @producer.ops: operations */
++ const struct xe_pagefault_ops *ops;
++#define XE_PAGEFAULT_PRODUCER_MSG_LEN_DW 4
++ /**
++ * @producer.msg: page fault message, used by producer in fault
++ * acknowledgment to formulate response to HW/FW interface.
++ * Included in the page-fault message because the producer
++ * typically receives the fault in a context where memory cannot
++ * be allocated (e.g., atomic context or the reclaim path).
++ */
++ u32 msg[XE_PAGEFAULT_PRODUCER_MSG_LEN_DW];
++ } producer;
++};
++
++/**
++ * struct xe_pagefault_queue: Xe pagefault queue (consumer)
++ *
++ * Used to capture all device page faults for deferred processing. Size this
++ * queue to absorb the device’s worst-case number of outstanding faults.
++ */
++struct xe_pagefault_queue {
++ /**
++ * @data: Data in queue containing struct xe_pagefault, protected by
++ * @lock
++ */
++ void *data;
++ /** @size: Size of queue in bytes */
++ u32 size;
++ /** @head: Head pointer in bytes, moved by producer, protected by @lock */
++ u32 head;
++ /** @tail: Tail pointer in bytes, moved by consumer, protected by @lock */
++ u32 tail;
++ /** @lock: protects page fault queue */
++ spinlock_t lock;
++ /** @worker: to process page faults */
++ struct work_struct worker;
++};
++
++#endif
drm-xe-hold-a-dma-buf-reference-for-imported-bos.patch
drm-i915-hdcp-move-to-using-intel_display-in-intel_hdcp.patch
drm-i915-hdcp-require-monotonically-increasing-seq_num_v.patch
+drm-i915-hdcp-skip-inactive-mst-connectors-when-building-stream-list.patch
+drm-i915-hdcp-check-streams-bounds-before-overflow.patch
+drm-xe-stub-out-new-pagefault-layer.patch
+drm-xe-pt-reset-current_op-in-xe_pt_update_ops_init.patch