7.8

CVE-2026-93192

drm/v3d: Clear queue->active_job when v3d_fence_create() fails

In the Linux kernel, the following vulnerability has been resolved:

drm/v3d: Clear queue->active_job when v3d_fence_create() fails

The run_job() callbacks for BIN, RENDER, TFU and CSD assign the incoming
job to queue->active_job before calling v3d_fence_create(). If
v3d_fence_create() fails, the callback returns NULL without clearing
active_job, leaving a dangling pointer.

Create a failure path in all run_job() callbacks that clears the active
job before returning NULL. The BIN path takes queue->queue_lock around the
clear as it races against v3d_overflow_mem_work(); RENDER, TFU and CSD
paths have no concurrent reader, so the clear is lock-free.
Daten sind bereitgestellt durch das CVE Programm von einer CVE Numbering Authority (CNA) (Unstrukturiert).
HerstellerLinux
≫
Produkt Linux
Default Statusunaffected
Version a783a09ee76d6259296dc6aeea2b6884fa526980
Version < bdeb73d7312100e00c3e643ff233f09b6ec114aa
Status affected
Version a783a09ee76d6259296dc6aeea2b6884fa526980
Version < 3a8aa74859dd73eaa76c55eb74da708e56ef51c5
Status affected
Version a783a09ee76d6259296dc6aeea2b6884fa526980
Version < 0b9878aba5cf93bc2b55ba9eb807757ce3239bec
Status affected
Version a783a09ee76d6259296dc6aeea2b6884fa526980
Version < 25a1669907512e927fab9ad4d4fb74ff57f63cd9
Status affected
HerstellerLinux
≫
Produkt Linux
Default Statusaffected
Version 5.3
Status affected
Version 0
Version < 5.3
Status unaffected
Version <= 6.12.*
Version 6.12.110
Status unaffected
Version <= 6.18.*
Version 6.18.52
Status unaffected
Version <= 7.2.*
Version 7.2.6
Status unaffected
Version <= *
Version 7.3-rc1
Status unaffected
VulnDex Vulnerability Enrichment
Diese Information steht angemeldeten Benutzern zur Verfügung. Login Login
Zu dieser CVE wurde keine Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 0.15% 0.048
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
416baaa9-dc9f-4396-8d5f-8c081fb06d67 7.8 1.8 5.9
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Es wurden noch keine Informationen zu CWE veröffentlicht.
https://git.kernel.org/stable/c/bdeb73d7312100e00c3e643ff233f09b6ec114aa
https://git.kernel.org/stable/c/3a8aa74859dd73eaa76c55eb74da708e56ef51c5
https://git.kernel.org/stable/c/0b9878aba5cf93bc2b55ba9eb807757ce3239bec
https://git.kernel.org/stable/c/25a1669907512e927fab9ad4d4fb74ff57f63cd9