CVE-2025-68802Improper Validation of Specified Quantity in Input in Linux

Severity
6.4MEDIUM
No vector
EPSS
0.0%
top 93.24%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedJan 13
Latest updateApr 17

Description

In the Linux kernel, the following vulnerability has been resolved: drm/xe: Limit num_syncs to prevent oversized allocations The exec and vm_bind ioctl allow userspace to specify an arbitrary num_syncs value. Without bounds checking, a very large num_syncs can force an excessively large allocation, leading to kernel warnings from the page allocator as below. Introduce DRM_XE_MAX_SYNCS (set to 1024) and reject any request exceeding this limit. " ------------[ cut here ]------------ WARNING: C

Affected Packages7 packages

Linuxlinux/linux_kernel6.8.06.12.64+1
Debianlinux/linux_kernel< 6.12.69-1+1
CVEListV5linux/linuxdd08ebf6c3525a7ea2186e636df064ea47281987e281d1fd6903a081ef023c341145ae92258e38d2+3
debiandebian/linux< linux 6.18.3-1 (forky)

🔴Vulnerability Details

3
OSV
drm/xe: Limit num_syncs to prevent oversized allocations2026-01-13
OSV
CVE-2025-68802: In the Linux kernel, the following vulnerability has been resolved: drm/xe: Limit num_syncs to prevent oversized allocations The exec and vm_bind ioct2026-01-13
GHSA
GHSA-8fv4-2ccq-j7r8: In the Linux kernel, the following vulnerability has been resolved: drm/xe: Limit num_syncs to prevent oversized allocations The exec and vm_bind io2026-01-13

📋Vendor Advisories

5
Ubuntu
Linux kernel (GCP) vulnerabilities2026-04-17
Ubuntu
Linux kernel (Real-time) vulnerabilities2026-04-17
Ubuntu
Linux kernel vulnerabilities2026-04-16
Red Hat
kernel: drm/xe: Limit num_syncs to prevent oversized allocations2026-01-13
Debian
CVE-2025-68802: linux - In the Linux kernel, the following vulnerability has been resolved: drm/xe: Lim...2025

🕵️Threat Intelligence

1
Wiz
CVE-2025-68802 Impact, Exploitability, and Mitigation Steps | Wiz