Vulnerabilities
- CVSS
- 7.0 High
- Vector
CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H- EPSS
- 0.17%
- Risk score
- 4.4
- Published
- 2026-08-10
- Status
- Published
In the Linux kernel, the following vulnerability has been resolved:
drm/xe/rtp: Add RING_FORCE_TO_NONPRIV_DENY to OA whitelists
Unconditionally whitelisting OA registers is a security violation. Set
RING_FORCE_TO_NONPRIV_DENY bit in OA nonpriv slots, so that OA registers
don't get whitelisted by default after probe, gt reset, resume and engine
reset.
(cherry picked from commit 90511bdcfda97211c01f1d945d4ea616578d8fca)
A flaw was found in the `drm/xe/rtp` component of the Linux kernel. This vulnerability arises from the unconditional whitelisting of Output/Availability (OA) registers, which is a security violation. By default, these registers could be whitelisted after system events such as probe, graphics translation (gt) reset, resume, and engine reset. This improper whitelisting could allow a local attacker to gain unauthorized access to privileged OA registers, potentially leading to a security bypass or information disclosure.
Coverage 1
threat-intel
Multiple vulnerabilities have been discovered in the Linux kernel of Debian. These vulnerabilities allow for privilege escalation, data compromise, and denial of service. The affected Debian versions are prior to 6.12.10…
Advisories and references