CVE-2026-23466Patch(linux / linux_kernel)

LOWCVSS 7.8 · HIGH

Signal is active with 1 mentions in latest observed window

Immediate actions

  • Patch linux linux_kernel systems immediately

Recommended action window: Monitor and triage in normal cycle

NVD description

In the Linux kernel, the following vulnerability has been resolved: drm/xe: Open-code GGTT MMIO access protection GGTT MMIO access is currently protected by hotplug (drm_dev_enter), which works correctly when the driver loads successfully and is later unbound or unloaded. However, if driver load fails, this protection is insufficient because drm_dev_unplug() is never called. Additionally, devm release functions cannot guarantee that all BOs with GGTT mappings are destroyed before the GGTT MMIO region is removed, as some BOs may be freed asynchronously by worker threads. To address this, introduce an open-coded flag, protected by the GGTT lock, that guards GGTT MMIO access. The flag is cleared during the dev_fini_ggtt devm release function to ensure MMIO access is disabled once teardown begins. (cherry picked from commit 4f3a998a173b4325c2efd90bdadc6ccd3ad9a431)

0.5/ 10 priority

Sources & remediation

Priority

LOW

Exploitation

NONE

PoC

NONE

Patch

AVAILABLE

Momentum

STABLE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • linux_kernel

Threat summary

  • Patch or workaround signal is available
  • 3 mentions across 2 observed days
  • Momentum state: stable

What's happening

  • Patch or workaround mentioned in 3 signals
  • Technical details provided in 2 signals
  • Peaked 1d ago at 2 mentions (2026-04-03); latest day: 1
  • 3 total mentions across 2 days

Affected systems

Vendors
Products
linux_kernel

1 version affected across 1 product

Deep dive

Activity timeline3 mentions / 2d
01122Mentions · 2026-04-03: 2Mentions · 2026-05-30: 1Patch / Workaround · 2026-04-03: 2Patch / Workaround · 2026-05-30: 1Technical Details · 2026-04-03: 1Technical Details · 2026-05-30: 104-0305-30
Signal classification1 categories
Patch
3100.0%
Referenced assets2 URLs
Classification over time
DateTotalLabels
2026-04-032
Patch2
2026-05-301
Patch1
Full discourse3 posts
  • DFIR Lab@DFIR_Lab
    Patch

    🚨 HIGH SEVERITY: CVE-2026-23466 (CVSS 7.8) Linux kernel drm/xe driver flaw allows local privilege escalation via GGTT MMIO access protection bypass. Affected: Linux kernel drm/xe module Patch available. #CVE #Vulnerability #PatchNow https://t.co/Gr4qWqt3S6

    Post summary

    The tweet announces CVE‑2026‑23466, a local privilege escalation vulnerability in the Linux kernel drm/xe driver, and notes that a patch is available.

    0000057
    32 followersView on X
  • Vulmon Vulnerability Feed@VulmonFeeds
    Patch

    CVE-2026-23466 In the Linux kernel, the following vulnerability has been resolved: drm/xe https://vulmon.com/vulnerabilitydetails?qid=CVE-2026-23466

    Post summary

    CVE‑2026‑23466, affecting the Linux kernel’s drm/xe component, has been resolved, indicating a patch or fix is available.

    0000039
    4.0K followersView on X
  • CVE@CVEnew
    Patch

    CVE-2026-23466 In the Linux kernel, the following vulnerability has been resolved: drm/xe: Open-code GGTT MMIO access protection GGTT MMIO access is currently protected by hotplug… https://www.cve.org/CVERecord?id=CVE-2026-23466

    Post summary

    CVE-2026-23466 in the Linux kernel has been addressed with a patch that protects GGTT MMIO access via hotplug, as noted in the CVE record.

    0000093
    56.9K followersView on X
CPE platform detail5 entries

5 of 5 entries

PartVendorProductVersionTarget SWTarget HW
OSlinuxlinux_kernel---
OSlinuxlinux_kernel7.0--
OSlinuxlinux_kernel7.0--
OSlinuxlinux_kernel7.0--
OSlinuxlinux_kernel7.0--

Explore more