Improper access control in Linux kernel - CVE-2026-68267
Published: August 12, 2026
Vulnerability details
The vulnerability allows a local user to bypass register access restrictions.
The vulnerability exists due to improper access control in the OA register whitelist handling in the xe DRM driver when initializing or resetting whitelist entries. A local user can access OA registers through non-privileged slots to bypass register access restrictions.
The issue can occur after probe, GT reset, resume, and engine reset.
Affected software
Debian Linux
linux (Debian package)
How to mitigate CVE-2026-68267
linux (Debian package) - update to 6.12.105-1