drm/xe/oa: Limit num_syncs to prevent oversized allocations
Published Jan 13, 2026
5.5
MEDIUMCVSS 3.1
EPSS 0.14%
Description
The OA open parameters did not validate num_syncs, allowing userspace to pass arbitrarily large values, potentially leading to excessive allocations.
Add check to ensure that num_syncs does not exceed DRM_XE_MAX_SYNCS, returning -EINVAL when the limit is violated.
v2: use XE_IOCTL_DBG() and drop duplicated check. (Ashutosh)
(cherry picked from commit e057b2d2b8d815df3858a87dffafa2af37e5945b)
Affected products
-
- Version 6.12.17StatusaffectedConstraints<6.12.64
- Version
-
- Version StatusaffectedConstraints
- Version StatusaffectedConstraints
- Version StatusaffectedConstraints
- Version
-
- Version 6.13StatusaffectedConstraints-
- Version 0StatusunaffectedConstraints<6.13
- Version 6.12.64StatusunaffectedConstraints<=6.12.*
- Version 6.18.3StatusunaffectedConstraints<=6.18.*
- Version 6.19StatusunaffectedConstraints<=*
- Version
Default status is the baseline for the product, each version can override it (e.g. patched versions marked unaffected).
| Vendor | Product | Default status | Versions | ||||||||||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
| Linux | Linux | unaffected |
| ||||||||||||||||||
| Linux | Linux | unaffected |
| ||||||||||||||||||
| Linux | Linux | affected |
|
- ≥ 6.12.17 · < 6.12.64
- ≥ 6.13.1 · < 6.18.3
- 6.13
- 6.19
- 6.19
- 6.19
- 6.19
- 6.19
- 6.19
- 6.19
- 6.19
No data.
Red Hat Enterprise Linux 10
kernel
Affected
Red Hat Enterprise Linux 6
kernel
Not affected
Red Hat Enterprise Linux 7
kernel
Not affected
Red Hat Enterprise Linux 7
kernel-rt
Not affected
Red Hat Enterprise Linux 8
kernel
Not affected
Red Hat Enterprise Linux 8
kernel-rt
Not affected
Red Hat Enterprise Linux 9
kernel
Affected
Red Hat Enterprise Linux 9
kernel-rt
Affected
| Product | Package | State | Advisory |
|---|---|---|---|
| Red Hat Enterprise Linux 10 | kernel | Affected | n/a |
| Red Hat Enterprise Linux 6 | kernel | Not affected | n/a |
| Red Hat Enterprise Linux 7 | kernel | Not affected | n/a |
| Red Hat Enterprise Linux 7 | kernel-rt | Not affected | n/a |
| Red Hat Enterprise Linux 8 | kernel | Not affected | n/a |
| Red Hat Enterprise Linux 8 | kernel-rt | Not affected | n/a |
| Red Hat Enterprise Linux 9 | kernel | Affected | n/a |
| Red Hat Enterprise Linux 9 | kernel-rt | Affected | n/a |
No package ranges for this CVE.
Remediation
Red Hat statement
This affects systems with Intel Xe discrete graphics hardware. Exploitation requires access to the DRM device file, typically available to users in the video group. The fix adds input validation to reject excessive num_syncs values.
Metrics
No CVSS v4.0 score for this CVE.
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
No CVSS v3.0 score for this CVE.
No CVSS v2.0 score for this CVE.
This CVE is not in the KEV list.
No CISA SSVC assessment for this CVE yet.
Estimated probability of exploitation in the wild in the next 30 days (FIRST EPSS). As of Oct 1, 2026.
Score over time
Jan–Oct 2026- EPSS v4
- EPSS v5
Percentile over time
- EPSS v4
- EPSS v5
Table of values (3 key points)
Flat stretches are collapsed; showing up to 120 newest points.
| Date | Score | Percentile | Model |
|---|---|---|---|
| Oct 1, 2026 | 0.14% (0.00141) | 2.88th | v5 (v2026.06.15) |
| Jun 15, 2026 | 0.12% (0.00121) | 2.21th | v5 (v2026.06.15) |
| Jan 14, 2026 | 0.02% (0.00017) | 3.13th | v4 (v2025.03.14) |
References (8)
- https://access.redhat.com/security/cve/CVE-2025-71076 Vendor Advisory
- https://bugzilla.redhat.com/show_bug.cgi?id=2429050 Issue Tracking
- https://git.kernel.org/stable/c/338849090ee610ff6d11e5e90857d2c27a4121ab Patch
- https://git.kernel.org/stable/c/b963636331fb4f3f598d80492e2fa834757198eb Patch
- https://git.kernel.org/stable/c/f8dd66bfb4e184c71bd26418a00546ebe7f5c17a Patch
- https://lore.kernel.org/linux-cve-announce/2026011326-CVE-2025-71076-19ff@gregkh/T
- https://nvd.nist.gov/vuln/detail/CVE-2025-71076
- https://www.cve.org/CVERecord?id=CVE-2025-71076
Change history (0)
No recorded changes yet.