CVE-2026-80915
Received Received - Intake

DRM XE Memory Allocation Flaw in Linux Kernel

Vulnerability report for CVE-2026-80915, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-09-09

Last updated on: 2026-09-09

Assigner: kernel.org

Description

In the Linux kernel, the following vulnerability has been resolved: drm/xe: Fix DPT allocation paths. Remove the fallback for VRAM to system memory, I tested it and that doesn't work at all, only a black screen with pipe fault errors were observed. On systems with media GT, extra latency is added when accessing stolen memory when the GT is in MC6. Since we additionally aren't counting how much memory is used for stolen and we could in theory fill up the entire stolen area with DPT's, avoid using stolen and only use the default memory region. Using stolen may also result in random system hangs under load. (cherry picked from commit a196406a3831291598fe8e73245914f7acffdfe0)

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-09-09
Last Modified
2026-09-09
Generated
2026-09-30
AI Q&A
2026-09-10
EPSS Evaluated
2026-09-29
NVD
EUVD

Affected Vendors & Products

Showing 1 associated CPE
Vendor Product Version / Range
linux linux_kernel *

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-UNKNOWN

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

This vulnerability in the Linux kernel involves incorrect handling of Display Page Table (DPT) allocation in the drm/xe driver. The issue arises from a fallback mechanism that attempts to move DPT allocations from Video RAM (VRAM) to system memory, which fails and causes a black screen with pipe fault errors. The fix removes this fallback entirely.

Detection Guidance

This vulnerability is specific to the Linux kernel's DRM/Xe driver and may cause black screens, pipe fault errors, or system hangs. Detection involves checking kernel logs for errors related to DRM/Xe or stolen memory access. Commands like dmesg | grep -i xe or dmesg | grep -i pipe_fault may help identify issues.

Impact Analysis

On systems with media GT, this vulnerability adds extra latency when accessing stolen memory during certain power states. It could also lead to random system hangs under load. The primary impact is system instability, crashes, or graphical failures during normal operation.

Compliance Impact

This vulnerability does not directly affect compliance with GDPR, HIPAA, or similar standards as it relates to a Linux kernel graphics driver issue causing system instability rather than data privacy or security breaches.

Mitigation Strategies

Update the Linux kernel to a patched version that includes the fix for this vulnerability. Avoid using stolen memory regions for DPT allocation by ensuring the kernel uses default memory regions. Monitor system logs for errors after applying updates.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-80915. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart