Out-of-bounds write in Linux kernel - CVE-2026-68264
Published: August 12, 2026
Vulnerability details
The vulnerability allows a local user to cause a denial of service.
The vulnerability exists due to an out-of-bounds write in xe_pt_update_ops_init() and the vm_bind path in the xe driver when retrying page table update preparation after lock contention or OOM eviction. A local user can trigger repeated retries to cause a denial of service.
The issue can corrupt SLUB-poisoned memory and lead to a subsequent use-after-free crash in xe_migrate_update_pgtables_cpu().
Affected software
Debian Linux
linux (Debian package)
How to mitigate CVE-2026-68264
linux (Debian package) - update to 6.12.105-1