Linux Kernel Oversized Allocation Vulnerability in DRM/xe/oa Component

Vulnerability

A vulnerability in the Linux kernel's Direct Rendering Manager (DRM) Xe Open Allocation (OA) component allows userspace to send excessively large synchronization values. This lack of validation could lead to excessive memory allocations. The issue has been addressed by implementing a check to ensure that the number of synchronization parameters does not exceed the defined maximum limit, with the kernel returning an error when this limit is breached.

Impact

Exploitation of this vulnerability could result in excessive memory allocations, potentially leading to memory exhaustion or denial-of-service conditions.

Remediation

Users can upgrade to the latest version of the Linux kernel where this vulnerability has been addressed. Instructions for downloading the patched version are available on the Linux Kernel Archive.

Added: Jan 13, 2026, 4:59 PM
Updated: Jan 13, 2026, 4:59 PM

Vulnerability Rating

Custom Algorithm
spread
9.0
impact
2.5
exploitability
4.0
remediation
7.7
relevance
2.0
threat
3.2
urgency
2.9
incentive
1.7

Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.