CVE-2025-68802 is a vulnerability in the Linux kernel's DRM/xe driver, specifically affecting Intel graphics. It allows a local attacker to trigger excessive memory allocations by providing an unvalidated large num_syncs value during exec or vm_bind ioctl calls, leading to kernel warnings and potential denial of service. The vulnerability has a FAUCET Risk Score of 39/100, indicating a moderate severity. There is no evidence of active exploitation, public exploit code, or Metasploit/Nuclei modules, though it has garnered significant community discussion and media coverage. A fix has been implemented by limiting num_syncs to DRM_XE_MAX_SYNCS (1024).
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
| Linux | Linux | 6.8CNA affecteddefault affected | |
| Linux | Linux | >= dd08ebf6c3525a7ea2186e636df064ea47281987, < 1d200017f55f829b9e376093bd31dfbec92081de, >= dd08ebf6c3525a7ea2186e636df064ea47281987, < 8e461304009135270e9ccf2d7e2dfe29daec9b60, >= dd08ebf6c3525a7ea2186e636df064ea47281987, < e281d1fd6903a081ef023c341145ae92258e38d2CNA affecteddefault unaffected |
CVSS version used by this source: FAUCET enrichment
Linux kernel (Raspberry Pi) vulnerabilities
May 7, 2026Linux kernel vulnerabilities
May 7, 2026Linux kernel vulnerabilities
Apr 23, 2026Linux kernel (GCP) vulnerabilities
Apr 17, 2026Linux kernel vulnerabilities
Apr 16, 2026kernel: drm/xe: Limit num_syncs to prevent oversized allocations
Jan 13, 2026