CVE-2026-80903
CVE CVE-2026-80903EUVD EUVD-2026-71662Published 2026-09-04T17:19:13.000Z
What the advisory describes
In the Linux kernel, the following vulnerability has been resolved: drm/xe/oa: Fix sync entry leak on OA config emit failure xe_oa_emit_oa_config() releases the sync entries and the syncs array only on its success path. When it fails before the point of no return (fence allocation, config buffer allocation or batch submission), it returns without touching stream->syncs. The stream open path handles such failures in the caller, but xe_oa_config_locked() propagates the error without any cleanup, so the syncs array and the fence references held by the parsed entries are leaked. The next config ioctl overwrites stream->syncs, making the memory unreachable for good. Clean up the parsed syncs when xe_oa_emit_oa_config() fails, matching the cleanup done by the stream open error path. (cherry picked from commit 8af97b3da2cfce04e6b457c6eb17ed3c1daf912b)
Source: EUVD (ENISA), in the words of the advisory.
Products the advisory names
These come from the advisory itself, not from any check we performed.
- Linux — Linux 9920c8b88c5cf2e44f4ff508dd3c0c96e4364db0 <948f346fe36e1d02353c3d61b1f6b66c6af91996; patch: 0; 9920c8b88c5cf2e44f4ff508dd3c0c96e4364db0 <027150e24e173a5dffe7f5ab3a6600618f634da2; patch: 6.12.105; 6.13; patch: 6.18.46; 9920c8b88c5cf2e44f4ff508dd3c0c96e4364db0 <8d33c4987cd162527375a3905017ae129ba7c3fe; patch: 7.2; f0ab9cd205d852a9024b73c71c8d8b217a04e8f0 <fcf7943b0a38568c547d7b5702de1d8190480616; 6.12.18 <6.12.105; patch: 7.1.10
The versions shown are the advisory's own. Patchlage compares no version numbers and derives no judgement from them — which version is installed is something a person has to look up.
Carried in the product catalogue
An estate covering these products can be recorded in Patchlage. An advisory about them appears in the next morning's situation report.
- Linux — Linux
Does this concern one of your customers?
This page cannot answer that — it does not know your estate. Whoever has recorded their environments gets the answer the morning after publication, together with a paragraph they can forward to the customer unedited.
Try it for 28 daysPatchlage reports hits and suspected hits. About everything else this system says nothing — neither this page nor the situation report ever claims that an estate is safe.