{"id":"CVE-2026-68274","aliases":[],"url":"https://o3.security/vulnerability/CVE-2026-68274","summary":"drm/xe/guc: Fix buffer overflow in steered register list allocation","details":"In the Linux kernel, the following vulnerability has been resolved:\n\ndrm/xe/guc: Fix buffer overflow in steered register list allocation\n\nThe size calculation for the steered register extarray uses only the\ngeometry DSS mask (g_dss_mask) to determine the number of entries to\nallocate:\n\n  total = bitmap_weight(gt->fuse_topo.g_dss_mask, ...) * steer_reg_num;\n\nHowever, the filling loop uses for_each_dss_steering(), which iterates\nover for_each_dss(), defined as the union of g_dss_mask and c_dss_mask\n(geometry + compute DSS). On platforms with compute-only DSS bits, the\nloop writes past the allocated buffer, corrupting adjacent slab objects.\n\nThis manifests as list_del corruption and SLUB redzone overwrites during\ndrm_managed_release on device unbind, since the overflow corrupts the\ndrmres list_head of neighboring allocations.\n\nFix by computing the allocation size using the union of both DSS masks,\nmatching the iteration pattern of for_each_dss_steering().\n\n--\nv2:\n- use bitmap_weighted_or() (Zhanjun)\n\n(cherry picked from commit 0a78a44f4901aa6c9263e66be7fce02282f1109f)","published":"2026-08-10T12:01:49.762Z","modified":"2026-08-14T04:02:39.979658048Z","cvss":{"score":7.8,"severity":"HIGH","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H"},"epss":null,"cisaKev":null,"exploitsKnown":null,"affectedPackages":[{"ecosystem":"Linux","name":"Kernel","fixedVersion":"6.18.44"}],"fix":null,"references":[{"type":"WEB","url":"https://git.kernel.org/stable/c/632ecc90e1ca5d3b6822bb4d08f84a175b6c42c0"},{"type":"WEB","url":"https://git.kernel.org/stable/c/a9a020f3c11eba6573b699f9cf9245a51b025ade"},{"type":"WEB","url":"https://git.kernel.org/stable/c/b485bfb45555163bfa5f565d6a3415fcb3035b02"},{"type":"ADVISORY","url":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/68xxx/CVE-2026-68274.json"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-68274"},{"type":"PACKAGE","url":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git"}],"provenance":{"sources":["OSV.dev","FIRST.org (EPSS)"],"lastVerified":"2026-08-14T04:02:39.979658048Z"}}