Answer in brief
CVE-2026-68265 records a High severity (CVSS 7.3) vulnerability in drm/xe/vm: Fix BO prefetch with CONSULT_MEM_ADVISE_PREF_LOC. The current sources do not mark it as known exploited. The current feed maps Linux/Linux (generic), Linux/Linux (generic). Check affected ranges and fixed versions before updating.
Analysis pending evidence review
HOL Guard separates source facts from reviewed analysis. See the methodology.
CVSS is 7.3. The current sources do not mark it as known exploited. Treat this as a source-backed prioritization signal, not a statement about your environment.
Analysis status
Analysis pending evidence review
Factual feed record only; HOL analysis is not approved for indexing. Read the methodology.
The current feed maps Linux/Linux (generic), Linux/Linux (generic). Check affected ranges and fixed versions before updating.
| Package | Affected range | Fixed version |
|---|---|---|
| Linux/Linuxgeneric | >=c1bb69a2e8e2d55c3725e304d8b8fd189ee43fbe <d256dac008d1d9e6378aa1a5454e89a8292d174c || >=c1bb69a2e8e2d55c3725e304d8b8fd189ee43fbe <c4affa4e8bc8086b4d3e8d6cf1055a624f813d72 || >=c1bb69a2e8e2d55c3725e304d8b8fd189ee43fbe <7bc597ce74bab4153b2009c92eccf889e9d74044 | d256dac008d1d9e6378aa1a5454e89a8292d174c, c4affa4e8bc8086b4d3e8d6cf1055a624f813d72, 7bc597ce74bab4153b2009c92eccf889e9d74044 |
| Linux/Linuxgeneric | 6.18 | Not reported |
Published upstream
Aug 10, 2026
Evidence: source:cvelist:source_dates:source-dates:recordSource modified
Aug 17, 2026
Evidence: source:cvelist:source_dates:source-dates:recordFirst seen by HOL
Aug 10, 2026
In the Linux kernel, the following vulnerability has been resolved: drm/xe/vm: Fix BO prefetch with CONSULT_MEM_ADVISE_PREF_LOC When prefetch region is DRM_XE_CONSULT_MEM_ADVISE_PREF_LOC for a BO VMA, the code used it as an index into region_to_mem_type[], causing an out-of-bounds access since the value is -1. Resolve the preferred location for BO VMAs directly: local VRAM on dGFX (using the BO's tile placement) or system memory on iGPU. Discovered using AI-assisted static analysis confirmed by Intel Product Security. v2: -Fix null dereference (cherry picked from commit d9a4906ac03be9f6ed3f3b45c56c866b867fd75b)
Quoted source text, attributed separately from HOL analysis.