Impact
A rounding bug in the Linux kernel's DRM/xe component causes the kernel to publish a region of memory that belongs to the compression hardware as free VRAM. When a userspace graphics driver allocates memory from this region, the GPU overwrites kernel data structures without needing a page table or a submission, leading to memory corruption and repeated crashes of the display manager. The main effects are loss of display (black screen), forced restarts of the graphical interface, and potential denial of service for the system.
Affected Systems
The bug affects all Linux kernel releases that include the DRM/xe code prior to the patch that rounds the CCS offset down instead of up. The affected vendor is Linux and product is the Linux kernel, meaning any distribution using an unpatched kernel is vulnerable. The fix is in commit 348c3db4f1520d36764ac8cae2492f50599714f6; environments running kernel versions older than this commit are impacted.
Risk and Exploitability
The CVSS score of 7.8 classifies the issue as high. The EPSS score of less than 1% indicates a very low likelihood of exploitation in the wild, and the vulnerability is not listed in the CISA KEV catalogue. The likely attack vector is local kernel exploitation via privileged users or compromised graphics drivers; an attacker would need to trigger the driver or load a malicious driver that requests memory in the corrupted region.
OpenCVE Enrichment