In the Linux kernel, the following vulnerability has been resolved:
drm/xe/pt: Reset currentop in xeptupdateops_init()
xeptupdateopsinit() fails to reset currentop to 0. On the vmbind path, opsexecute() calls xeptupdateopsprepare() inside the xevalidationguard() / drmexecuntilalllocked() loop. When that loop retries due to lock contention or OOM eviction (drmexecretryoncontention() / xevalidationretryonoom()), xeptupdateopsprepare() runs again on the same vops, and each call to bindopprepare() increments currentop without resetting it.
After N retries currentop exceeds the array size allocated by xevmaopsalloc(), causing an out-of-bounds write into SLUB-poisoned memory and a subsequent UAF crash in xemigrateupdatepgtablescpu() when reading the corrupted pt_op->bind.
Also reset needssvmlock and needs_invalidation which are derived in the same prepare pass and would otherwise cause wrong migrate ops selection and redundant TLB invalidation on retry.
Fix this by resetting currentop, needssvmlock and needsinvalidation in xeptupdateopsinit().
v2 (Matt): - Add details in commit message. - Add Fixes tag and Cc to stable@vger.kernel.org
(cherry picked from commit 046045543e530605c441063535e7dca0075369a6)
{
"osv_generated_from": "https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/68xxx/CVE-2026-68264.json",
"cna_assigner": "Linux"
}