SB20260812274 - Observable discrepancy in Linux kernel i915 gem driver
Published: August 12, 2026
Breakdown by Severity
- Low
- Medium
- High
- Critical
Description
This security bulletin contains information about 1 vulnerability.
1) Observable discrepancy (CVE-ID: CVE-2026-68269)
CWE-ID: CWE-203 - Observable discrepancy
CVSSv4: 4.8 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N]
The vulnerability allows a local user to disclose sensitive information.
The vulnerability exists due to improper restriction of speculative execution in the parallel submission slot handling in set_proto_ctx_engines_parallel_submit() when processing a userspace-controlled parallel submission slot. A local user can supply a crafted slot value to disclose sensitive information.
Remediation
Install update from vendor's website.
References
- https://git.kernel.org/stable/c/45db277b2e1e34bcc99a0852026791108339ec3e
- https://git.kernel.org/stable/c/4a27275d275971c9ea29d3d240ea4a224ad368a2
- https://git.kernel.org/stable/c/914a76a9f08366434bf595700f62026b7a19a9cc
- https://git.kernel.org/stable/c/be393175306694de5da1d1a23a8ea4149baa09f1
- https://git.kernel.org/stable/c/c41a54619e95f860bf2950dd679ab353380ecd2b