{"api_version":"1","generated_at":"2026-09-11T22:32:24+00:00","cve":"CVE-2026-80915","urls":{"html":"https://cve.report/CVE-2026-80915","api":"https://cve.report/api/cve/CVE-2026-80915.json","docs":"https://cve.report/api","cve_org":"https://www.cve.org/CVERecord?id=CVE-2026-80915","nvd":"https://nvd.nist.gov/vuln/detail/CVE-2026-80915"},"summary":{"title":"drm/xe: Fix DPT allocation paths.","description":"In the Linux kernel, the following vulnerability has been resolved:\n\ndrm/xe: Fix DPT allocation paths.\n\nRemove the fallback for VRAM to system memory, I tested it and that\ndoesn't work at all, only a black screen with pipe fault errors were\nobserved.\n\nOn systems with media GT, extra latency is added when accessing stolen\nmemory when the GT is in MC6. Since we additionally aren't counting how\nmuch memory is used for stolen and we could in theory fill up the\nentire stolen area with DPT's, avoid using stolen and only use the\ndefault memory region.\n\nUsing stolen may also result in random system hangs under load.\n\n(cherry picked from commit a196406a3831291598fe8e73245914f7acffdfe0)","state":"PUBLISHED","assigner":"Linux","published_at":"2026-09-09 17:17:46","updated_at":"2026-09-09 17:17:46"},"problem_types":[],"metrics":[],"references":[{"url":"https://git.kernel.org/stable/c/c457e2c845ccbf2224386029f3da4937ba424db0","name":"https://git.kernel.org/stable/c/c457e2c845ccbf2224386029f3da4937ba424db0","refsource":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","tags":[],"title":"","mime":"","httpstatus":"","archivestatus":"0"},{"url":"https://git.kernel.org/stable/c/f03415030579163f791c978741af7f1f2f6510b7","name":"https://git.kernel.org/stable/c/f03415030579163f791c978741af7f1f2f6510b7","refsource":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","tags":[],"title":"","mime":"","httpstatus":"","archivestatus":"0"},{"url":"https://git.kernel.org/stable/c/491c499295fb0b90308b230b0a1075dcdf7f4d12","name":"https://git.kernel.org/stable/c/491c499295fb0b90308b230b0a1075dcdf7f4d12","refsource":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","tags":[],"title":"","mime":"","httpstatus":"","archivestatus":"0"},{"url":"https://git.kernel.org/stable/c/fc648757908304aedbad74f74bf58192aec383db","name":"https://git.kernel.org/stable/c/fc648757908304aedbad74f74bf58192aec383db","refsource":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","tags":[],"title":"","mime":"","httpstatus":"","archivestatus":"0"},{"url":"https://www.cve.org/CVERecord?id=CVE-2026-80915","name":"CVE Program record","refsource":"CVE.ORG","tags":["canonical"]},{"url":"https://nvd.nist.gov/vuln/detail/CVE-2026-80915","name":"NVD vulnerability detail","refsource":"NVD","tags":["canonical","analysis"]}],"affected":[{"source":"CNA","vendor":"Linux","product":"Linux","version":"affected 775d0adc01a55fe0458139330415d86bb3533efe 491c499295fb0b90308b230b0a1075dcdf7f4d12 git","platforms":[]},{"source":"CNA","vendor":"Linux","product":"Linux","version":"affected 775d0adc01a55fe0458139330415d86bb3533efe f03415030579163f791c978741af7f1f2f6510b7 git","platforms":[]},{"source":"CNA","vendor":"Linux","product":"Linux","version":"affected 775d0adc01a55fe0458139330415d86bb3533efe c457e2c845ccbf2224386029f3da4937ba424db0 git","platforms":[]},{"source":"CNA","vendor":"Linux","product":"Linux","version":"affected 775d0adc01a55fe0458139330415d86bb3533efe fc648757908304aedbad74f74bf58192aec383db git","platforms":[]},{"source":"CNA","vendor":"Linux","product":"Linux","version":"affected 4854ac2f88e2168ee4da2b152c6711772a8149aa git","platforms":[]},{"source":"CNA","vendor":"Linux","product":"Linux","version":"affected 6.11.3 6.12 semver","platforms":[]},{"source":"CNA","vendor":"Linux","product":"Linux","version":"affected 6.12","platforms":[]},{"source":"CNA","vendor":"Linux","product":"Linux","version":"unaffected 6.12 semver","platforms":[]},{"source":"CNA","vendor":"Linux","product":"Linux","version":"unaffected 6.12.106 6.12.* semver","platforms":[]},{"source":"CNA","vendor":"Linux","product":"Linux","version":"unaffected 6.18.47 6.18.* semver","platforms":[]},{"source":"CNA","vendor":"Linux","product":"Linux","version":"unaffected 7.1.11 7.1.* semver","platforms":[]},{"source":"CNA","vendor":"Linux","product":"Linux","version":"unaffected 7.2 * original_commit_for_fix","platforms":[]}],"timeline":[],"solutions":[],"workarounds":[],"exploits":[],"credits":[],"nvd_cpes":[],"vendor_comments":[],"enrichments":{"kev":null,"epss":null,"legacy_qids":[]},"source_records":{"cve_program":{"containers":{"cna":{"affected":[{"defaultStatus":"unaffected","product":"Linux","programFiles":["drivers/gpu/drm/xe/display/xe_fb_pin.c"],"repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","vendor":"Linux","versions":[{"lessThan":"491c499295fb0b90308b230b0a1075dcdf7f4d12","status":"affected","version":"775d0adc01a55fe0458139330415d86bb3533efe","versionType":"git"},{"lessThan":"f03415030579163f791c978741af7f1f2f6510b7","status":"affected","version":"775d0adc01a55fe0458139330415d86bb3533efe","versionType":"git"},{"lessThan":"c457e2c845ccbf2224386029f3da4937ba424db0","status":"affected","version":"775d0adc01a55fe0458139330415d86bb3533efe","versionType":"git"},{"lessThan":"fc648757908304aedbad74f74bf58192aec383db","status":"affected","version":"775d0adc01a55fe0458139330415d86bb3533efe","versionType":"git"},{"status":"affected","version":"4854ac2f88e2168ee4da2b152c6711772a8149aa","versionType":"git"},{"lessThan":"6.12","status":"affected","version":"6.11.3","versionType":"semver"}]},{"defaultStatus":"affected","product":"Linux","programFiles":["drivers/gpu/drm/xe/display/xe_fb_pin.c"],"repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","vendor":"Linux","versions":[{"status":"affected","version":"6.12"},{"lessThan":"6.12","status":"unaffected","version":"0","versionType":"semver"},{"lessThanOrEqual":"6.12.*","status":"unaffected","version":"6.12.106","versionType":"semver"},{"lessThanOrEqual":"6.18.*","status":"unaffected","version":"6.18.47","versionType":"semver"},{"lessThanOrEqual":"7.1.*","status":"unaffected","version":"7.1.11","versionType":"semver"},{"lessThanOrEqual":"*","status":"unaffected","version":"7.2","versionType":"original_commit_for_fix"}]}],"cpeApplicability":[{"nodes":[{"cpeMatch":[{"criteria":"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*","versionEndExcluding":"6.12.106","versionStartIncluding":"6.12","vulnerable":true},{"criteria":"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*","versionEndExcluding":"6.18.47","versionStartIncluding":"6.12","vulnerable":true},{"criteria":"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*","versionEndExcluding":"7.1.11","versionStartIncluding":"6.12","vulnerable":true},{"criteria":"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*","versionEndExcluding":"7.2","versionStartIncluding":"6.12","vulnerable":true},{"criteria":"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*","versionStartIncluding":"6.11.3","vulnerable":true}],"negate":false,"operator":"OR"}]}],"descriptions":[{"lang":"en","value":"In the Linux kernel, the following vulnerability has been resolved:\n\ndrm/xe: Fix DPT allocation paths.\n\nRemove the fallback for VRAM to system memory, I tested it and that\ndoesn't work at all, only a black screen with pipe fault errors were\nobserved.\n\nOn systems with media GT, extra latency is added when accessing stolen\nmemory when the GT is in MC6. Since we additionally aren't counting how\nmuch memory is used for stolen and we could in theory fill up the\nentire stolen area with DPT's, avoid using stolen and only use the\ndefault memory region.\n\nUsing stolen may also result in random system hangs under load.\n\n(cherry picked from commit a196406a3831291598fe8e73245914f7acffdfe0)"}],"providerMetadata":{"dateUpdated":"2026-09-09T16:13:13.979Z","orgId":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","shortName":"Linux"},"references":[{"url":"https://git.kernel.org/stable/c/491c499295fb0b90308b230b0a1075dcdf7f4d12"},{"url":"https://git.kernel.org/stable/c/f03415030579163f791c978741af7f1f2f6510b7"},{"url":"https://git.kernel.org/stable/c/c457e2c845ccbf2224386029f3da4937ba424db0"},{"url":"https://git.kernel.org/stable/c/fc648757908304aedbad74f74bf58192aec383db"}],"title":"drm/xe: Fix DPT allocation paths.","x_generator":{"engine":"bippy-1.2.0"}}},"cveMetadata":{"assignerOrgId":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","assignerShortName":"Linux","cveId":"CVE-2026-80915","datePublished":"2026-09-09T16:13:13.979Z","dateReserved":"2026-08-26T14:34:25.801Z","dateUpdated":"2026-09-09T16:13:13.979Z","state":"PUBLISHED"},"dataType":"CVE_RECORD","dataVersion":"5.2"},"nvd":{"publishedDate":"2026-09-09 17:17:46","lastModifiedDate":"2026-09-09 17:17:46","problem_types":[],"metrics":[],"configurations":[]},"legacy_mitre":{"record":{"CveYear":"2026","CveId":"80915","Ordinal":"1","Title":"drm/xe: Fix DPT allocation paths.","CVE":"CVE-2026-80915","Year":"2026"},"notes":[{"CveYear":"2026","CveId":"80915","Ordinal":"1","NoteData":"In the Linux kernel, the following vulnerability has been resolved:\n\ndrm/xe: Fix DPT allocation paths.\n\nRemove the fallback for VRAM to system memory, I tested it and that\ndoesn't work at all, only a black screen with pipe fault errors were\nobserved.\n\nOn systems with media GT, extra latency is added when accessing stolen\nmemory when the GT is in MC6. Since we additionally aren't counting how\nmuch memory is used for stolen and we could in theory fill up the\nentire stolen area with DPT's, avoid using stolen and only use the\ndefault memory region.\n\nUsing stolen may also result in random system hangs under load.\n\n(cherry picked from commit a196406a3831291598fe8e73245914f7acffdfe0)","Type":"Description","Title":"drm/xe: Fix DPT allocation paths."}]}}}