Junglewise Threat Intelligence

CVE-2026-31390: Linux kernel memory leak in Intel Xe DRM driver

CVE-2026-31390 · Severity: medium · CVSS 5.5 · Published 2026-04-03

Technologies: Linux Kernel. Vendors: Linux.

Executive brief

A memory leak vulnerability was identified in the Linux kernel's Intel Xe graphics driver. The issue occurs when the system fails to properly release memory during certain error conditions when managing graphics memory. A local attacker could exploit this to gradually consume system memory, potentially leading to a system crash or denial of service.

Technical details

A memory leak exists in the xe_vm_madvise_ioctl function within the Intel Xe DRM driver (drivers/gpu/drm/xe/xe_vm_madvise.c). The vulnerability is caused by an incorrect error handling path: when the check_bo_args_are_sane() validation fails, the code jumps to a label that bypasses the kfree() call for allocated VMAs. A local user with access to the DRM device can trigger this leak by providing invalid arguments to the madvise IOCTL, leading to kernel memory exhaustion. The issue has been resolved by introducing a proper cleanup label (free_vmas) to ensure resources are freed during validation failures.

Affected products

  • Linux Linux kernel 6.18 to 6.18.20, 6.19 to 6.19.10, 7.0-rc1, 7.0-rc2

Timeline

  • 2026-04-03: advisory: Initial disclosure by kernel.org
  • 2026-03-25: patched: Patches merged into stable branches 6.18.y and 6.19.y

References