Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1336 CNY

100%

CVE-2026-68305— drm/xe/vf: Add drm_dev guards when detaching CCS read/write buffers

CVSS 7.8 · High EPSS 0.13% · P3

Affected Version Matrix 6

VendorProductVersion RangeStatus
LinuxLinux864690cf4dd62482b6dd049d82c509886c904303< 523ed2831ee55b2a1edabdea96781651f9df9685affected
864690cf4dd62482b6dd049d82c509886c904303< 4c92afb4c143526d340545ca581e88e6952ea511affected
6.18affected
< 6.18unaffected
7.1.6≤ 7.1.*unaffected
7.2≤ *unaffected
Get alerts for future matching vulnerabilitiesLog in to subscribe

I. Basic Information for CVE-2026-68305

Vulnerability Information

Have questions about the vulnerability? See if Shenlong's analysis helps!
View Shenlong Deep Dive ↗

Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.

Vulnerability Title
drm/xe/vf: Add drm_dev guards when detaching CCS read/write buffers
Source: CVE Program / CVE List V5
Vulnerability Description
In the Linux kernel, the following vulnerability has been resolved: drm/xe/vf: Add drm_dev guards when detaching CCS read/write buffers CCS read/write buffers are freed during BO destruction. In some cases, BOs may be destroyed after the device is unbound but while the DRM structure remains valid, leading to NULL pointer dereferences when accessing device resources. BUG: kernel NULL pointer dereference, address: 0000000000000000 PGD 0 P4D 0 Oops: Oops: 0000 [#1] SMP NOPTI CPU: 0 UID: 0 PID: 9376 Comm: xe_pat Not tainted 7.2.0-rc2+ #1 PREEMPT(lazy) RIP: 0010:xe_sriov_vf_ccs_rw_update_bb_addr+0x4d/0xa0 [xe] RSP: 0018:ffffcf304110b9c8 EFLAGS: 00010246 RAX: ffff8a85c38a0a00 RBX: 00000000810ef000 RCX: 0000000000000000 RDX: 0000000000000000 RSI: 0000000000000000 RDI: ffff8a85c39c1888 RBP: ffffcf304110b9e8 R08: 0000000000000000 R09: 0000000000000000 R10: 0000000000000000 R11: 0000000000000000 R12: ffff8a85c39c1888 R13: 0000000000000000 R14: ffff8a85c39b4f28 R15: ffff8a85c3885000 FS: 0000000000000000(0000) GS:ffff8a878b809000(0000) knlGS:0000000000000000 CS: 0010 DS: 0000 ES: 0000 CR0: 0000000080050033 CR2: 0000000000000000 CR3: 000000010314a002 CR4: 0000000000772ef0 PKRU: 55555554 Call Trace: <TASK> xe_migrate_ccs_rw_copy_clear+0x98/0x120 [xe] xe_sriov_vf_ccs_detach_bo+0x2c/0x60 [xe] xe_ttm_bo_delete_mem_notify+0xc8/0xe0 [xe] ttm_bo_cleanup_memtype_use+0x26/0x80 [ttm] ttm_bo_release+0x29e/0x2d0 [ttm] ttm_bo_fini+0x39/0x70 [ttm] xe_gem_object_free+0x1f/0x30 [xe] drm_gem_object_free+0x1d/0x40 ttm_bo_vm_close+0x5f/0x90 [ttm] remove_vma+0x2c/0x70 tear_down_vmas+0x63/0xf0 exit_mmap+0x20d/0x3f0 __mmput+0x45/0x170 mmput+0x31/0x40 do_exit+0x2ba/0xac0 do_group_exit+0x2d/0xb0 __x64_sys_exit_group+0x18/0x20 x64_sys_call+0x14a0/0x2390 do_syscall_64+0xdd/0x640 ? count_memcg_events+0xea/0x240 ? handle_mm_fault+0x1ec/0x2f0 (cherry picked from commit 1ae415a6eefe5004954a1d352b1718faca8844ef)
Source: CVE Program / CVE List V5
CVSS Information
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Source: CVE Program / CVE List V5
Vulnerability Type
N/A
Source: CVE Program / CVE List V5
Vulnerability Title
Linux kernel 安全漏洞
Source: CNNVD (China National Vulnerability Database)
Vulnerability Description
Linux kernel是美国Linux基金会开源的一个操作系统内核。 Linux kernel 6.18版本存在安全漏洞,该漏洞源于设备解除绑定后缓冲区对象可能被销毁,访问设备资源时导致空指针取消引用。
Source: CNNVD (China National Vulnerability Database)
CVSS Information
N/A
Source: CNNVD (China National Vulnerability Database)
Vulnerability Type
N/A
Source: CNNVD (China National Vulnerability Database)

Affected Products

VendorProductAffected VersionsCPESubscribe
LinuxLinux 864690cf4dd62482b6dd049d82c509886c904303 ~ 523ed2831ee55b2a1edabdea96781651f9df9685 -
LinuxLinux 6.18 -

II. Public POCs for CVE-2026-68305

#POC DescriptionSource LinkShenlong Link
AI-Generated POCPremium

No public POC found.

Login to generate AI POC

III. Intelligence Information for CVE-2026-68305

登录查看更多情报信息。

Patches & Fixes for CVE-2026-68305 (2)

Same Patch Batch · Linux · 2026-08-10 · 344 CVEs total

CVE-2026-681619.8 CRITICALsctp: close UDP tunnel sockets during netns teardown
CVE-2026-681239.8 CRITICALopenvswitch: fix GSO userspace truncation underflow
CVE-2026-681279.8 CRITICALila: reload IPv6 header after pskb_may_pull in checksum adjust
CVE-2026-681179.8 CRITICALtipc: clear sock->sk on the failed-insert path in tipc_sk_create()
CVE-2026-681369.8 CRITICALnet: gro: fix double aggregation of flush-marked skbs
CVE-2026-681379.8 CRITICALnet/x25: fix use-after-free in x25_kill_by_neigh()
CVE-2026-683009.8 CRITICALsctp: auth: verify auth requirement when auth_chunk is NULL
CVE-2026-681449.8 CRITICALphonet: pep: fix use-after-free in pep_get_sb()
CVE-2026-681549.8 CRITICALlibceph: reject zero bucket types in crush_decode
CVE-2026-681569.8 CRITICALlibceph: refresh auth->authorizer_buf{,_len} after authorizer update
CVE-2026-681589.8 CRITICALlibceph: Fix multiplication overflow in decode_new_up_state_weight()
CVE-2026-681599.8 CRITICALlibceph: bound pg_{temp,upmap,upmap_items} length to CEPH_PG_MAX_SIZE
CVE-2026-681609.8 CRITICALceph: fix pre-auth out-of-bounds read on snaptrace in ceph_handle_caps()
CVE-2026-681709.8 CRITICALmptcp: fix stale skb->sk reference on subflow close
CVE-2026-683029.8 CRITICALamt: re-read skb header pointers after every pull
CVE-2026-684269.8 CRITICALxfrm: fix stale skb->prev after async crypto steals a GSO segment
CVE-2026-683889.8 CRITICALsmb/client: handle overlapping allocated ranges in fallocate
CVE-2026-683859.8 CRITICALs390/checksum: Fix csum_partial() without vector facility
CVE-2026-683819.8 CRITICALksmbd: pin conn during async oplock break notification
CVE-2026-681249.6 CRITICALmctp: serial: handle zero-length frames to prevent rx buffer overflow

Showing top 20 of 344 CVEs. View all on vendor page &rarr; →

IV. Related Vulnerabilities

V. Comments for CVE-2026-68305

No comments yet


Leave a comment