AUGUST 15, 2026
Live Feed
Back to database
Case File

CVE-2026-72311

UNKNOWN · CVSS N/A

Source: NVD + CISA KEV + EPSS · Published 2026-08-15 · Last synced 2026-08-15

CyberRota Analysis

AI-Generated

The vulnerability affects the Linux kernel's handling of memory advice via the `xe_vm_madvise_ioctl()` function, specifically in the management of the VMA (Virtual Memory Area) array during error handling. If an L2 flush validation fails, the function improperly skips the cleanup of allocated memory, leading to a memory leak that could impact system performance and stability. Linux system administrators and developers should prioritize this issue to ensure efficient memory management and prevent potential resource exhaustion in their environments.

CVE
CVE-2026-72311
Severity
UNKNOWN
CVSS
N/A
EPSS
N/A
Linux

Original NVD Description

In the Linux kernel, the following vulnerability has been resolved: drm/xe: free madvise VMA array on L2 flush failure xe_vm_madvise_ioctl() allocates madvise_range.vmas in get_vmas(). After get_vmas() succeeds with at least one VMA, error paths must go through free_vmas so the array is released before the madvise details are destroyed. The L2 flush validation path added for PAT madvise rejects some SVM/userptr ranges after get_vmas() has succeeded, but jumps directly to madv_fini. This skips kfree(madvise_range.vmas), leaking the VMA array on each failed ioctl. Jump to free_vmas instead, matching the other validation failure paths after get_vmas() has succeeded. (cherry picked from commit c3a1c3579b1250060da73507a4acef712974c78a)