CVE-2026-68243 PUBLISHED

drm/i915/gem: Fix NULL deref in I915_CONTEXT_PARAM_SSEU

Assigner: Linux
Reserved: 30.07.2026 Published: 10.08.2026 Updated: 10.08.2026

In the Linux kernel, the following vulnerability has been resolved:

drm/i915/gem: Fix NULL deref in I915_CONTEXT_PARAM_SSEU

Setting context engine slot N into I915_ENGINE_CLASS_INVALID / I915_ENGINE_CLASS_INVALID_NONE and attempting to apply I915_CONTEXT_PARAM_SSEU to the same slot N will deref NULL. Fix that.

Discovered using AI-assisted static analysis confirmed by Intel Product Security.

(cherry picked from commit 36eda5b5c2d40da41cc0a5403c26986237cf9e87)

Product Status

Vendor Linux
Product Linux
Versions Default: unaffected
  • affected from d4433c7600f794623d6802395542cf4ca4f1b1f9 to edd2edaca52ada833c341c8b264aaea9dd93369c (excl.)
  • affected from d4433c7600f794623d6802395542cf4ca4f1b1f9 to 9923c223d38fcd9602f41cc31d480e5299d9a38e (excl.)
  • affected from d4433c7600f794623d6802395542cf4ca4f1b1f9 to 726f27bca93e6c83b263542669132ee1d0eb693e (excl.)
  • affected from d4433c7600f794623d6802395542cf4ca4f1b1f9 to 97f236379f06a5082d37c6a764edd56bb58a94cd (excl.)
  • affected from d4433c7600f794623d6802395542cf4ca4f1b1f9 to 2b56757a9a7456825eb668fde92299e01c5e2721 (excl.)
Vendor Linux
Product Linux
Versions Default: affected
  • Version 5.15 is affected
  • unaffected from 0 to 5.15 (excl.)
  • unaffected from 6.6.148 to 6.6.* (incl.)
  • unaffected from 6.12.101 to 6.12.* (incl.)
  • unaffected from 6.18.42 to 6.18.* (incl.)
  • unaffected from 7.1.6 to 7.1.* (incl.)
  • unaffected from 7.2-rc3 to * (incl.)

References