Lack of data validation In linux

Description

A resource exhaustion vulnerability was found in the Linux kernel's Intel Xe graphics driver. The exec and vm_bind ioctls accept a user-specified num_syncs value without bounds checking. A malicious user can specify an extremely large value, forcing the kernel to attempt an oversized memory allocation that triggers page allocator warnings and potential denial of service.

Mitigation

Update Impact

Minimal update. May introduce new vulnerabilities or breaking changes.

Ecosystem
Package
Affected version
Patched versions