CVE-2026-68274
Last modified
CVE-2026-68274 is a vulnerability of currently unknown severity. In the Linux kernel, the following vulnerability has been resolved: drm/xe/guc: Fix buffer overflow in steered register list allocation The size calculation for the steered register extarray uses only the geometry DSS mask (g_dss_mask) to determine the number of entries to allocate: total = bitmap_weight(gt->fuse_topo.g_dss_mask, ...) * steer_reg_num; However, the filling loop uses for_each_dss_steering(), which iterates over for_each_dss(), defined as the union of g_dss_mask and c_dss_mask (geometry + compute DSS). On platforms with compute-only DSS bits, the loop writes past the allocated buffer, corrupting adjacent slab objects. This manifests as list_del corruption and SLUB redzone overwrites during drm_managed_release on device unbind, since the overflow corrupts the drmres list_head of neighboring allocations. Fix by computing the allocation size using the union of both DSS masks, matching the iteration pattern of for_each_dss_steering(). -- v2: - use bitmap_weighted_or() (Zhanjun) (cherry picked from commit 0a78a44f4901aa6c9263e66be7fce02282f1109f).
Description
In the Linux kernel, the following vulnerability has been resolved: drm/xe/guc: Fix buffer overflow in steered register list allocation The size calculation for the steered register extarray uses only the geometry DSS mask (g_dss_mask) to determine the number of entries to allocate: total = bitmap_weight(gt->fuse_topo.g_dss_mask, ...) * steer_reg_num; However, the filling loop uses for_each_dss_steering(), which iterates over for_each_dss(), defined as the union of g_dss_mask and c_dss_mask (geometry + compute DSS). On platforms with compute-only DSS bits, the loop writes past the allocated buffer, corrupting adjacent slab objects. This manifests as list_del corruption and SLUB redzone overwrites during drm_managed_release on device unbind, since the overflow corrupts the drmres list_head of neighboring allocations. Fix by computing the allocation size using the union of both DSS masks, matching the iteration pattern of for_each_dss_steering(). -- v2: - use bitmap_weighted_or() (Zhanjun) (cherry picked from commit 0a78a44f4901aa6c9263e66be7fce02282f1109f)
Affected Software
Source: CNA advisory (CVE.org). NVD analysis pending.
| Vendor | Product | Versions |
|---|---|---|
| Linux | Linux | >= b170d696c1e2226713471d810c63b1162335079f, < b485bfb45555163bfa5f565d6a3415fcb3035b02; >= b170d696c1e2226713471d810c63b1162335079f, < a9a020f3c11eba6573b699f9cf9245a51b025ade; >= b170d696c1e2226713471d810c63b1162335079f, < 632ecc90e1ca5d3b6822bb4d08f84a175b6c42c0 |
| Linux | Linux | 6.13 |
References
Timeline
- Published
- Last Modified
- Status
- Received
Frequently Asked Questions
What is CVE-2026-68274?
How severe is CVE-2026-68274?
How do I fix CVE-2026-68274?
How Strix Helps
- How Strix found a critical auth bypass in etcdStrix autonomously discovered a critical authentication bypass in etcd, later designated CVE-2026-33413.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2026
- CVE-2026-68268In the Linux kernel, the following vulnerability has been re…
- CVE-2026-68269In the Linux kernel, the following vulnerability has been re…
- CVE-2026-68270In the Linux kernel, the following vulnerability has been re…
- CVE-2026-68271In the Linux kernel, the following vulnerability has been re…
- CVE-2026-68272In the Linux kernel, the following vulnerability has been re…
- CVE-2026-68273In the Linux kernel, the following vulnerability has been re…
- CVE-2026-68275In the Linux kernel, the following vulnerability has been re…
- CVE-2026-68276In the Linux kernel, the following vulnerability has been re…
- CVE-2026-68277In the Linux kernel, the following vulnerability has been re…
- CVE-2026-68278In the Linux kernel, the following vulnerability has been re…
- CVE-2026-68279In the Linux kernel, the following vulnerability has been re…
- CVE-2026-6828The Fluent Forms – Customizable Contact Forms, Survey, Quiz,…6.4
Are you affected by CVE-2026-68274?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
