CVE-2026-68267

high

Description

In the Linux kernel, the following vulnerability has been resolved: drm/xe/rtp: Add RING_FORCE_TO_NONPRIV_DENY to OA whitelists Unconditionally whitelisting OA registers is a security violation. Set RING_FORCE_TO_NONPRIV_DENY bit in OA nonpriv slots, so that OA registers don't get whitelisted by default after probe, gt reset, resume and engine reset. (cherry picked from commit 90511bdcfda97211c01f1d945d4ea616578d8fca)

References

https://git.kernel.org/stable/c/e70086a3a06d276b4a5d9a2c51c9330c6cf72780

https://git.kernel.org/stable/c/9852aa87ecba95d7bf9fb94a9d6c4f69312c9682

https://git.kernel.org/stable/c/7982678fa21eda02a9111d2646be6762b5e3a64d

https://git.kernel.org/stable/c/1e6d07abbc0c41cb3259042794ad3deca79dd14e

Details

Source: Mitre, NVD

Published: 2026-08-10

Updated: 2026-08-10

Risk Information

CVSS v2

Base Score: 5.6

Vector: CVSS2#AV:L/AC:L/Au:N/C:N/I:P/A:C

Severity: Medium

CVSS v3

Base Score: 7.8

Vector: CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

Severity: High