{
  "affected": [
    {
      "ranges": [
        {
          "events": [
            {
              "introduced": "b170d696c1e2226713471d810c63b1162335079f"
            },
            {
              "fixed": "b485bfb45555163bfa5f565d6a3415fcb3035b02"
            },
            {
              "fixed": "a9a020f3c11eba6573b699f9cf9245a51b025ade"
            },
            {
              "fixed": "632ecc90e1ca5d3b6822bb4d08f84a175b6c42c0"
            }
          ],
          "repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
          "type": "GIT"
        }
      ]
    },
    {
      "package": {
        "ecosystem": "Linux",
        "name": "Kernel"
      },
      "ranges": [
        {
          "events": [
            {
              "introduced": "6.13.0"
            },
            {
              "fixed": "6.18.44"
            }
          ],
          "type": "ECOSYSTEM"
        },
        {
          "events": [
            {
              "introduced": "6.19.0"
            },
            {
              "fixed": "7.1.6"
            }
          ],
          "type": "ECOSYSTEM"
        }
      ]
    }
  ],
  "database_specific": {
    "cna_assigner": "Linux",
    "osv_generated_from": "https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/68xxx/CVE-2026-68274.json"
  },
  "details": "In the Linux kernel, the following vulnerability has been resolved:\n\ndrm/xe/guc: Fix buffer overflow in steered register list allocation\n\nThe size calculation for the steered register extarray uses only the\ngeometry DSS mask (g_dss_mask) to determine the number of entries to\nallocate:\n\n  total = bitmap_weight(gt-\u003efuse_topo.g_dss_mask, ...) * steer_reg_num;\n\nHowever, the filling loop uses for_each_dss_steering(), which iterates\nover for_each_dss(), defined as the union of g_dss_mask and c_dss_mask\n(geometry + compute DSS). On platforms with compute-only DSS bits, the\nloop writes past the allocated buffer, corrupting adjacent slab objects.\n\nThis manifests as list_del corruption and SLUB redzone overwrites during\ndrm_managed_release on device unbind, since the overflow corrupts the\ndrmres list_head of neighboring allocations.\n\nFix by computing the allocation size using the union of both DSS masks,\nmatching the iteration pattern of for_each_dss_steering().\n\n--\nv2:\n- use bitmap_weighted_or() (Zhanjun)\n\n(cherry picked from commit 0a78a44f4901aa6c9263e66be7fce02282f1109f)",
  "id": "CVE-2026-68274",
  "modified": "2026-08-18T03:31:18.249275764Z",
  "published": "2026-08-10T12:01:49.762Z",
  "references": [
    {
      "type": "WEB",
      "url": "https://git.kernel.org/stable/c/632ecc90e1ca5d3b6822bb4d08f84a175b6c42c0"
    },
    {
      "type": "WEB",
      "url": "https://git.kernel.org/stable/c/a9a020f3c11eba6573b699f9cf9245a51b025ade"
    },
    {
      "type": "WEB",
      "url": "https://git.kernel.org/stable/c/b485bfb45555163bfa5f565d6a3415fcb3035b02"
    },
    {
      "type": "ADVISORY",
      "url": "https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/68xxx/CVE-2026-68274.json"
    },
    {
      "type": "ADVISORY",
      "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-68274"
    },
    {
      "type": "PACKAGE",
      "url": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git"
    }
  ],
  "schema_version": "1.9.0",
  "severity": [
    {
      "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H",
      "type": "CVSS_V3"
    }
  ],
  "summary": "drm/xe/guc: Fix buffer overflow in steered register list allocation"
}