Memory leak in Linux kernel - CVE-2026-80903
Published: September 5, 2026
Vulnerability details
The vulnerability allows a local user to cause a denial of service.
The vulnerability exists due to improper cleanup in xe_oa_config_locked() when handling an OA configuration ioctl after OA configuration emission fails. A local user can invoke configuration ioctls that result in repeated unreleased sync entries and fence references to cause a denial of service.
The failure can occur during fence allocation, configuration-buffer allocation, or batch submission before the point of no return.