CSIRTS // UNIFIED SECURITY ADVISORY FEEDSYS ● ONLINE · POWERED BY INTELFUSIONS.COM

CVE-2026-68254

mediumCVSS 5.5covered by 3 sourcesfirst seen 2026-08-10
In the Linux kernel, the following vulnerability has been resolved: drm/i915/vrr: require valid min/max vfreq for VRR Ensure the EDID provided min/max vfreq are valid. Most scenarios are already covered (by coincidence) through the checks in intel_vrr_is_capable() and intel_vrr_is_in_range(), but be more explicit about it. At worst, a zero min_vfreq could lead to a division by zero in intel_vrr_compute_vmax(). Discovered using AI-assisted static analysis confirmed by Intel Product Security. (cherry picked from commit 1765cf59f517b02f3b0591fe5120930d08bddeb6)

CSIRTS triage

What
The Intel i915 DRM driver does not validate minimum and maximum refresh frequency parameters for Variable Refresh Rate mode.
Who is affected
Linux systems with Intel integrated graphics using the i915 driver with VRR support.
Urgency
Medium priority; invalid parameters can cause display malfunction or system instability.
Action
Apply Linux kernel patch for CVE-2026-68254 when available from your distribution.

AI-assisted analysis generated from the source advisory — verify against the original.

⚡ Watch CVE-2026-68254

Get an email if CVE-2026-68254 is added to CISA KEV, gains public exploit code, or a new advisory cites it — max one per day, one-click unsubscribe.

Exploitation outlook

Advisory coverage (3)

External references

NVD record for CVE-2026-68254

CVE.org record

Embed the live status

CVE-2026-68254 live status badge — this badge updates automatically when the KEV or exploit status changes. How to embed it →

[![CVE-2026-68254 status](https://www.csirts.com/badge/CVE-2026-68254)](https://www.csirts.com/cve/CVE-2026-68254)