Executive brief
A security vulnerability was identified in the Linux kernel's Intel Xe graphics driver. The issue allows a local attacker to bypass standard memory security protections on systems with integrated graphics. By specifically configuring how the graphics processor accesses memory, an attacker could potentially read sensitive data left behind in memory by other applications or the operating system, even after that memory has been supposedly cleared.
Technical details
A vulnerability in the Intel Xe driver's UAPI (specifically `xe_vm_madvise_ioctl`) allowed the use of the `XE_COH_NONE` coherency mode with CPU-cached memory buffers on integrated GPUs (iGPUs). On iGPU platforms where the GPU and CPU share the Last Level Cache (LLC), using a non-coherent PAT index allows the GPU to bypass CPU caches and read directly from DRAM. Because the kernel's page-clearing operations may remain 'dirty' in the CPU cache and not yet committed to DRAM, a GPU read can access stale, uncleared data from previously freed pages belonging to other processes. The fix introduces validation in `check_pat_args_are_sane` to reject these configurations on iGPU hardware.
Affected products
- Linux Linux Kernel v6.18+
Timeline
- 2026-04-17: disclosed: Initial patch submission by Intel
- 2026-04-29: patched: Mainline kernel commit 4e5591c2fc1b30f4ea5e2eab4c3a695acc404e39
- 2026-06-08: advisory: CVE-2026-46309 published