CVE-2026-68267

Source
https://cve.org/CVERecord?id=CVE-2026-68267
Import Source
https://storage.googleapis.com/osv-test-cve-osv-conversion/osv-output/CVE-2026-68267.json
JSON Data
https://api.test.osv.dev/v1/vulns/CVE-2026-68267
Downstream
Published
2026-08-10T12:01:42Z
Modified
2026-08-18T03:31:00Z
Summary
drm/xe/rtp: Add RING_FORCE_TO_NONPRIV_DENY to OA whitelists
Details

In the Linux kernel, the following vulnerability has been resolved:

drm/xe/rtp: Add RING_FORCE_TO_NONPRIV_DENY to OA whitelists

Unconditionally whitelisting OA registers is a security violation. Set RING_FORCE_TO_NONPRIV_DENY bit in OA nonpriv slots, so that OA registers don't get whitelisted by default after probe, gt reset, resume and engine reset.

(cherry picked from commit 90511bdcfda97211c01f1d945d4ea616578d8fca)

Database specific
{
    "cna_assigner": "Linux",
    "osv_generated_from": "https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/68xxx/CVE-2026-68267.json"
}
References

Affected packages

Git / git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git

Affected ranges

Type
GIT
Repo
https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git
Events
Introduced
828a8eaf37c3fac6ba048995f55f1647a4ac542d
Fixed
9852aa87ecba95d7bf9fb94a9d6c4f69312c9682
Fixed
7982678fa21eda02a9111d2646be6762b5e3a64d
Fixed
1e6d07abbc0c41cb3259042794ad3deca79dd14e
Fixed
e70086a3a06d276b4a5d9a2c51c9330c6cf72780

Database specific

source
"https://storage.googleapis.com/osv-test-cve-osv-conversion/osv-output/CVE-2026-68267.json"

Linux / Kernel

Package

Name
Kernel

Affected ranges

Type
ECOSYSTEM
Events
Introduced
6.11.0
Fixed
6.12.103
Type
ECOSYSTEM
Events
Introduced
6.13.0
Fixed
6.18.44
Type
ECOSYSTEM
Events
Introduced
6.19.0
Fixed
7.1.6

Database specific

source
"https://storage.googleapis.com/osv-test-cve-osv-conversion/osv-output/CVE-2026-68267.json"