Improper access control in Linux kernel - CVE-2026-68267

 

Improper access control in Linux kernel - CVE-2026-68267

Published: August 12, 2026


Vulnerability identifier: #VU142044
CSH Severity: Low
CVSS v4: 4.8 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:L/VI:L/VA:N/SC:N/SI:N/SA:N]
CVE-ID: CVE-2026-68267
CWE-ID: CWE-284
Exploitation vector: Local access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a local user to bypass register access restrictions.

The vulnerability exists due to improper access control in the OA register whitelist handling in the xe DRM driver when initializing or resetting whitelist entries. A local user can access OA registers through non-privileged slots to bypass register access restrictions.

The issue can occur after probe, GT reset, resume, and engine reset.


Affected software

Linux kernel
Debian Linux
linux (Debian package)

How to mitigate CVE-2026-68267

Install security update from vendor's repository.

Linux kernel - update to 7.0 rc3
linux (Debian package) - update to 6.12.105-1

External References

Related Security Bulletins