Skip to main content

Over 150 LLM Providers · Over 5,300 Models The most extensible AI-powered pentesting platform. Open source. Star on GitHub

CVE-2026-68271

Published Aug 10, 2026 EPSS 0.18% (7th pctl)

Overview

CVE-2026-68271 is a known-severity vulnerability. It was published on August 10, 2026.

Technical Description

In the Linux kernel, the following vulnerability has been resolved:

drm/nouveau: fix reversed error cleanup order in ucopy functions

nouveau_uvmm_vm_bind_ucopy() and nouveau_exec_ucopy() place their error

cleanup labels in allocation order rather than reverse allocation order.

On a u_memcpya() failure for in_sync.s, the goto to err_free_ops (or

err_free_pushs) frees the first allocation and then falls through to

err_free_ins, which calls u_free() on args->in_sync.s.

Since args->in_sync.s still holds the ERR_PTR returned by the failed

u_memcpya(), and ERR_PTR values are not caught by ZERO_OR_NULL_PTR(),

kvfree() proceeds to dereference it, which can result in a kernel oops.

A failure for out_sync.s instead jumps to err_free_ins and skips freeing

the first allocation, leading to a memory leak.

Fix by swapping the cleanup label order so resources are freed in the

correct reverse allocation sequence.

Remediation

Check the references section for vendor advisories, patches, and mitigation guidance. If immediate patching is not possible, review the CVSS vector to understand the attack surface and apply compensating controls such as network segmentation or access restrictions.

Frequently Asked Questions

What is CVE-2026-68271?

CVE-2026-68271 is a known-severity vulnerability. It was published on August 10, 2026.

How severe is CVE-2026-68271?

CVSS score information is not yet available for this vulnerability. Check back as the CVE record is updated by NVD analysts.

How do I fix or remediate CVE-2026-68271?

Check the references section for vendor advisories, patches, and mitigation guidance. If immediate patching is not possible, review the CVSS vector to understand the attack surface and apply compensating controls such as network segmentation or access restrictions.

How can CyberStrike help with CVE-2026-68271?

CyberStrike's AI-powered security agents can automatically detect CVE-2026-68271 across your infrastructure using autonomous pentesting, DAST scanning, and HackBrowser. The platform continuously monitors for known vulnerabilities and provides actionable remediation guidance prioritized by real-world exploitability.