Back

MEDIUM

drm/xe/oa: Limit num_syncs to prevent oversized allocations

Published Jan 13, 2026

Description

The OA open parameters did not validate num_syncs, allowing userspace to pass arbitrarily large values, potentially leading to excessive allocations.

Add check to ensure that num_syncs does not exceed DRM_XE_MAX_SYNCS, returning -EINVAL when the limit is violated.

v2: use XE_IOCTL_DBG() and drop duplicated check. (Ashutosh)

(cherry picked from commit e057b2d2b8d815df3858a87dffafa2af37e5945b)

Affected products

Remediation

Red Hat statement

This affects systems with Intel Xe discrete graphics hardware. Exploitation requires access to the DRM device file, typically available to users in the video group. The fix adds input validation to reject excessive num_syncs values.

Metrics

References (8)

Change history (0)

No recorded changes yet.

Sources
CVE.org / MITRE
Status PUBLISHED
Assigner Linux
Published Jan 13, 2026
Updated May 23, 2026
Reserved Jan 13, 2026
NVD
Status Analyzed
Modified Jun 17, 2026
Red Hat
Severity Low
Public date Jan 13, 2026