Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1336 CNY

100%

CVE-2026-72360— drm/xe/pf: Don't attempt to process FAST_REQ or EVENT relays

CVSS 8.4 · High EPSS 0.17% · P7

Affected Version Matrix 10

VendorProductVersion RangeStatus
LinuxLinux98e62805921cebcd2fcac3692037ca2ebef63b4a< 499be4b5d64209e9f18c9442f9fbeef7155ae900affected
98e62805921cebcd2fcac3692037ca2ebef63b4a< adc7dda728ca3e340a413e3bbc10cf159e1866a4affected
98e62805921cebcd2fcac3692037ca2ebef63b4a< a4208d8032abd7f591581994f31e23b80b8fe659affected
98e62805921cebcd2fcac3692037ca2ebef63b4a< ed8b0d731892c68b41ecbd27c952af284816dec1affected
6.11affected
< 6.11unaffected
6.12.97≤ 6.12.*unaffected
6.18.40≤ 6.18.*unaffected
… +2 more rows
Get alerts for future matching vulnerabilitiesLog in to subscribe

I. Basic Information for CVE-2026-72360

Vulnerability Information

Have questions about the vulnerability? See if Shenlong's analysis helps!
View Shenlong Deep Dive ↗

Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.

Vulnerability Title
drm/xe/pf: Don't attempt to process FAST_REQ or EVENT relays
Source: CVE Program / CVE List V5
Vulnerability Description
In the Linux kernel, the following vulnerability has been resolved: drm/xe/pf: Don't attempt to process FAST_REQ or EVENT relays Currently defined VF/PF relay actions use regular REQUEST messages only and the PF shouldn't attempt to handle FAST_REQUEST nor EVENT messages as this would result in breaking the VFPF ABI protocol and also might trigger an assert on the PF side. (cherry picked from commit 1714d360fc5ae2e0886a69e979095d9c7ff3568a)
Source: CVE Program / CVE List V5
CVSS Information
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:N/I:H/A:H
Source: CVE Program / CVE List V5
Vulnerability Type
N/A
Source: CVE Program / CVE List V5
Vulnerability Title
Linux kernel 安全漏洞
Source: CNNVD (China National Vulnerability Database)
Vulnerability Description
Linux kernel是美国Linux基金会开源的一个操作系统内核。 Linux kernel 6.11版本存在安全漏洞,该漏洞源于PF尝试处理FAST_REQUEST或EVENT消息,可能导致破坏VFPF ABI协议并触发PF侧断言。
Source: CNNVD (China National Vulnerability Database)
CVSS Information
N/A
Source: CNNVD (China National Vulnerability Database)
Vulnerability Type
N/A
Source: CNNVD (China National Vulnerability Database)

Affected Products

VendorProductAffected VersionsCPESubscribe
LinuxLinux 98e62805921cebcd2fcac3692037ca2ebef63b4a ~ 499be4b5d64209e9f18c9442f9fbeef7155ae900 -
LinuxLinux 6.11 -

II. Public POCs for CVE-2026-72360

#POC DescriptionSource LinkShenlong Link
AI-Generated POCPremium

No public POC found.

Login to generate AI POC

III. Intelligence Information for CVE-2026-72360

登录查看更多情报信息。

Patches & Fixes for CVE-2026-72360 (4)

Same Patch Batch · Linux · 2026-08-15 · 846 CVEs total

CVE-2026-7430910.0 CRITICALvdpa/octeon_ep: fix IRQ-to-ring mapping in interrupt handler
CVE-2026-7242110.0 CRITICALipv4: fib: Don't ignore error route in local/main tables.
CVE-2026-7240810.0 CRITICALgeneve: gate GRO hint in geneve_gro_complete() on gs->gro_hint
CVE-2026-7240710.0 CRITICALgeneve: validate inner network offset in geneve_gro_complete()
CVE-2026-7427910.0 CRITICALcrypto: cavium/cpt - fix DMA cleanup using wrong loop index
CVE-2026-7428010.0 CRITICALcrypto: marvell/octeontx - fix DMA cleanup using wrong loop index
CVE-2026-7447510.0 CRITICALvxlan: use neigh_ha_snapshot() in route_shortcircuit()
CVE-2026-724939.9 CRITICALnet: serialize netif_running() check in enqueue_to_backlog()
CVE-2026-743619.8 CRITICALnvme: fix FDP fdpcidx bounds check
CVE-2026-724369.8 CRITICALnetfilter: ipset: Don't use test_bit() in lockless RCU readers in hash types
CVE-2026-720659.8 CRITICALnet: mana: Validate the packet length reported by the NIC
CVE-2026-744739.8 CRITICALvxlan: use pskb_network_may_pull() in route_shortcircuit()
CVE-2026-742689.8 CRITICALtcp: clear sock_ops cb flags before force-closing a child socket
CVE-2026-722179.8 CRITICALSUNRPC: Bound-check xdr_buf_to_bvec() stores before writing
CVE-2026-723989.8 CRITICALsctp: add INIT verification after cookie unpacking
CVE-2026-744749.8 CRITICALvxlan: use pskb_network_may_pull() for transmit path header pulls
CVE-2026-723559.8 CRITICALnetfs: Fix barriering when walking subrequest list
CVE-2026-724429.8 CRITICALnetfilter: flowtable: fix and simplify IP6IP6 tunnel handling
CVE-2026-743849.8 CRITICALnvme-multipath: fix flex array size in struct nvme_ns_head
CVE-2026-720699.8 CRITICALlocking/rt: Fix the incorrect RCU protection in rt_spin_unlock()

Showing top 20 of 846 CVEs. View all on vendor page &rarr; →

IV. Related Vulnerabilities

V. Comments for CVE-2026-72360

No comments yet


Leave a comment