PatchSiren

PatchSiren cyber security CVE debrief

CVE-2026-90047 Linux CVE debrief

A vulnerability in the Linux kernel's drm/xe component has been identified, where the allocation of memory for the flat CCS storage was incorrectly calculated, leading to the publication of compression hardware memory as free memory. This could result in memory being overwritten by the compression hardware, potentially causing system instability or security issues.

Vendor
Linux
Product
Unknown
CVSS
HIGH 7.8
CISA KEV
Not listed in stored evidence
Original CVE published
2026-09-16
Original CVE updated
2026-09-28
Advisory published
2026-09-16
Advisory updated
2026-09-28

Who should care

Linux kernel developers and maintainers, Linux distribution maintainers, and users of Linux-based systems should assess exposure and apply patches or mitigations as necessary. Affected operators and platforms may experience memory corruption or overwriting, potentially causing system instability or security issues. Vulnerability management and security teams should review the vulnerability and implement compensating controls if necessary. System operators,

Why it matters

A vulnerability in the Linux kernel's drm/xe component could lead to memory corruption or overwriting, potentially causing system instability or security issues. Linux kernel developers and maintainers, Linux distribution maintainers, and users of Linux-based systems should assess exposure and apply patches or mitigations as necessary.

  • Memory corruption or overwriting due to incorrect allocation
  • Potential system instability or crashes
  • Security risks due to exposure of compression hardware memory

Technical summary

The vulnerability was caused by a rounding error in the calculation of the flat CCS storage offset, leading to the allocation of memory that belongs to the compression hardware as usable VRAM. This was resolved by changing the rounding from up to down to the page size the allocator works in. The fix ensures that memory allocated for the flat CCS storage does not overlap with the compression hardware memory, preventing potential memory corruption or overwriting. Linux kernel developers and maintainers should assess the vulnerability and apply patches or mitigations as necessary.

Defensive priority

High

Recommended defensive actions

  • Review and apply the patch to update the Linux kernel
  • Verify the Linux kernel version and update if necessary
  • Monitor system stability and security
  • Check relevant monitoring, detection, and logs for exposed assets that need extra review
  • Track exceptions, retest remediated assets, and close the item only after evidence is documented
  • Confirm whether affected product deployments exist in managed environments and assign an owner for follow-up
  • Review compensating controls for exposed systems while remediation is scheduled and verified

Evidence notes

The vulnerability was introduced due to a rounding error in the calculation of the flat CCS storage offset, which led to the allocation of memory that belongs to the compression hardware as usable VRAM. This issue was resolved by changing the rounding from up to down to the page size the allocator works in.

Sources and references

Verified primary and authoritative sources

  • CVE-2026-90047 CVE Program record

    Publisher, destination, and source semantics verified

    URL: https://www.cve.org/CVERecord?id=CVE-2026-90047

    CVE Program - Official CVE Program record with source-provided CVE metadata.

  • CVE-2026-90047 NVD vulnerability detail

    Publisher, destination, and source semantics verified

    URL: https://nvd.nist.gov/vuln/detail/CVE-2026-90047

    NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.

Supplemental references

  • Source reference

    Unverified legacy reference

    URL: https://git.kernel.org/stable/c/348c3db4f1520d36764ac8cae2492f50599714f6

    416baaa9-dc9f-4396-8d5f-8c081fb06d67

  • Source reference

    Unverified legacy reference

    URL: https://git.kernel.org/stable/c/818bebeb63dd6bf5f4e07e145f6cdbace520a34c

    416baaa9-dc9f-4396-8d5f-8c081fb06d67

  • Source reference

    Unverified legacy reference

    URL: https://git.kernel.org/stable/c/c96477e0cabf55bfbdf078078e9de1c8024f8060

    416baaa9-dc9f-4396-8d5f-8c081fb06d67

Methodology and review provenance

AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.