Answer in brief
CVE-2026-72362 records a Unknown severity vulnerability in drm/xe/pt: Fix NULL pointer dereference in xe_pt_zap_ptes_entry(). The current sources do not mark it as known exploited. The current feed maps Linux/Linux (generic), Linux/Linux (generic). Check affected ranges and fixed versions before updating.
Analysis pending evidence review
HOL Guard separates source facts from reviewed analysis. See the methodology.
A CVSS score is not reported in the current record. The current sources do not mark it as known exploited. Treat this as a source-backed prioritization signal, not a statement about your environment.
Analysis status
Analysis pending evidence review
Factual feed record only; HOL analysis is not approved for indexing. Read the methodology.
The current feed maps Linux/Linux (generic), Linux/Linux (generic). Check affected ranges and fixed versions before updating.
| Package | Affected range | Fixed version |
|---|---|---|
| Linux/Linuxgeneric | >=dd08ebf6c3525a7ea2186e636df064ea47281987 <ff330ce16c846b70164ff0eb544c81219d4c5c08 || >=dd08ebf6c3525a7ea2186e636df064ea47281987 <78b1074966d290d4517f42bc81e13c4349368d12 || >=dd08ebf6c3525a7ea2186e636df064ea47281987 <d94b9922b2ae5ee6e900f8da0bd537b251c6110c || >=dd08ebf6c3525a7ea2186e636df064ea47281987 <3feeb667197bd58a17f4edfdbcad249ffcb3c864 | ff330ce16c846b70164ff0eb544c81219d4c5c08, 78b1074966d290d4517f42bc81e13c4349368d12, d94b9922b2ae5ee6e900f8da0bd537b251c6110c, 3feeb667197bd58a17f4edfdbcad249ffcb3c864 |
| Linux/Linuxgeneric | 6.8 | Not reported |
Published upstream
Aug 15, 2026
Evidence: source:cvelist:source_dates:source-dates:recordSource modified
Aug 15, 2026
Evidence: source:cvelist:source_dates:source-dates:recordFirst seen by HOL
Aug 15, 2026
In the Linux kernel, the following vulnerability has been resolved: drm/xe/pt: Fix NULL pointer dereference in xe_pt_zap_ptes_entry() The page-table walk framework may pass a NULL *child pointer for unpopulated entries. xe_pt_zap_ptes_entry() called container_of(*child) before checking for NULL, then dereferenced the result, causing a crash. Move the container_of() call after a NULL guard, so the function returns early instead of proceeding with an invalid pointer. XE_WARN_ON is kept to help root cause the issue, but we now bail instead of crashing the driver. v2: Comment that triggering XE_WARN_ON is unexpected behavior (Matt Brost) (cherry picked from commit b9297d19d9df5d4b6c994648570c5dcd1cac68ff)
Quoted source text, attributed separately from HOL analysis.
Answer in brief
CVE-2026-72362 records a Unknown severity vulnerability in drm/xe/pt: Fix NULL pointer dereference in xe_pt_zap_ptes_entry(). The current sources do not mark it as known exploited. The current feed maps Linux/Linux (generic), Linux/Linux (generic). Check affected ranges and fixed versions before updating.
Analysis pending evidence review
HOL Guard separates source facts from reviewed analysis. See the methodology.
A CVSS score is not reported in the current record. The current sources do not mark it as known exploited. Treat this as a source-backed prioritization signal, not a statement about your environment.
Analysis status
Analysis pending evidence review
Factual feed record only; HOL analysis is not approved for indexing. Read the methodology.
The current feed maps Linux/Linux (generic), Linux/Linux (generic). Check affected ranges and fixed versions before updating.
| Package | Affected range | Fixed version |
|---|---|---|
| Linux/Linuxgeneric | >=dd08ebf6c3525a7ea2186e636df064ea47281987 <ff330ce16c846b70164ff0eb544c81219d4c5c08 || >=dd08ebf6c3525a7ea2186e636df064ea47281987 <78b1074966d290d4517f42bc81e13c4349368d12 || >=dd08ebf6c3525a7ea2186e636df064ea47281987 <d94b9922b2ae5ee6e900f8da0bd537b251c6110c || >=dd08ebf6c3525a7ea2186e636df064ea47281987 <3feeb667197bd58a17f4edfdbcad249ffcb3c864 | ff330ce16c846b70164ff0eb544c81219d4c5c08, 78b1074966d290d4517f42bc81e13c4349368d12, d94b9922b2ae5ee6e900f8da0bd537b251c6110c, 3feeb667197bd58a17f4edfdbcad249ffcb3c864 |
| Linux/Linuxgeneric | 6.8 | Not reported |
Published upstream
Aug 15, 2026
Evidence: source:cvelist:source_dates:source-dates:recordSource modified
Aug 15, 2026
Evidence: source:cvelist:source_dates:source-dates:recordFirst seen by HOL
Aug 15, 2026
In the Linux kernel, the following vulnerability has been resolved: drm/xe/pt: Fix NULL pointer dereference in xe_pt_zap_ptes_entry() The page-table walk framework may pass a NULL *child pointer for unpopulated entries. xe_pt_zap_ptes_entry() called container_of(*child) before checking for NULL, then dereferenced the result, causing a crash. Move the container_of() call after a NULL guard, so the function returns early instead of proceeding with an invalid pointer. XE_WARN_ON is kept to help root cause the issue, but we now bail instead of crashing the driver. v2: Comment that triggering XE_WARN_ON is unexpected behavior (Matt Brost) (cherry picked from commit b9297d19d9df5d4b6c994648570c5dcd1cac68ff)
Quoted source text, attributed separately from HOL analysis.