Description
In the Linux kernel, the following vulnerability has been resolved:

drm/v3d: Associate BOs with every job that accesses them

A submission can expand into a chain of jobs (e.g. bin + render + cache
clean). Implicit synchronization in v3d_submit_lock_reservations() is gated
on each job's bo[], but the BO list was only ever attached to the last job
of the chain. When that last job is a trailing CACHE_CLEAN job, the job
that actually consumes the BOs (that is, a RENDER or CSD job) was left with
bo_count == 0 and picked up no implicit dependencies. It could therefore
be dispatched to the hardware and read a BO while another context was still
writing it, leading to data corruption.

Attach the BOs to the job that consumes them, so (1) it acquires the
correct implicit dependencies during reservation locking and (2) they are
kept mapped until the end of the submission. Give it references to all
consuming job's BOs through v3d_job_reference_bos() instead of looking the
handles up a second time; that avoids a redundant lookup and guarantees
both jobs reference the exact same objects.

As the CACHE_CLEAN job now carries a BO array as well, add a per-job
`has_implicit_dep` flag so that only the consuming jobs take implicit
dependencies. The CACHE_CLEAN job (a global flush) and the BIN job (binning
waiting on another context is not a realistic scenario) are excluded.
Published: 2026-09-17
Score: n/a
EPSS: < 1% Very Low
KEV: No
Impact: Data corruption
Action: Assess Impact
AI Analysis

Impact

A race condition has been discovered in the Linux kernel DRM V3D driver where buffer objects (BOs) are only attached to the last job in a chain of jobs. The consuming job—typically a rendering operation—ends up with an empty BO list, causing it to miss implicit dependencies. Consequently, the job may be dispatched to the hardware and read a BO that another context is still writing to, leading to data corruption. This flaw allows a malicious or malfunctioning job to produce corrupted graphics data or potentially exploit the corrupted state to gain higher privileges, although the exact impact depends on the kernel configuration and the attacker’s capabilities.

Affected Systems

This vulnerability affects all Linux kernel builds that include the DRM V3D driver prior to the application of the fix referenced in the commit logs. No specific kernel version range is enumerated, implying that any kernel containing the vulnerable driver is susceptible until the patch is integrated. The issue is limited to the V3D hardware abstraction within the DRM subsystem; other DRM drivers are not involved.

Risk and Exploitability

The EPSS score for this flaw is reported as less than 1%, indicating a low likelihood of exploitation. It is not listed in the CISA KEV catalog, suggesting no known exploited variants as of the latest data. The attack vector is inferred to be local or privileged, requiring access to submit DRM jobs that trigger the problematic job chain. With proper access control, the risk is moderate, but the potential for data corruption or privilege escalation warrants timely remediation.

Generated by OpenCVE AI on September 19, 2026 at 06:57 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Upgrade the system to a Linux kernel that incorporates the fix from commit 7244dd0f12629484a1936dc5c5837670d8d9f80c. Ensure all relevant vendor patches are applied to bring the DRM V3D driver up to date.
  • If an immediate kernel upgrade is not feasible, restrict or isolate the DRM V3D subsystem by limiting job submission permissions to trusted users or disabling the DRV’s job chaining features when possible.
  • Continuously monitor kernel logs for signs of GPU job failures or abnormal crashes, and apply the patch as soon as it becomes available to prevent data integrity issues.

Generated by OpenCVE AI on September 19, 2026 at 06:57 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Sat, 19 Sep 2026 07:15:00 +0000

Type Values Removed Values Added
Weaknesses CWE-362

Thu, 17 Sep 2026 16:30:00 +0000

Type Values Removed Values Added
Description In the Linux kernel, the following vulnerability has been resolved: drm/v3d: Associate BOs with every job that accesses them A submission can expand into a chain of jobs (e.g. bin + render + cache clean). Implicit synchronization in v3d_submit_lock_reservations() is gated on each job's bo[], but the BO list was only ever attached to the last job of the chain. When that last job is a trailing CACHE_CLEAN job, the job that actually consumes the BOs (that is, a RENDER or CSD job) was left with bo_count == 0 and picked up no implicit dependencies. It could therefore be dispatched to the hardware and read a BO while another context was still writing it, leading to data corruption. Attach the BOs to the job that consumes them, so (1) it acquires the correct implicit dependencies during reservation locking and (2) they are kept mapped until the end of the submission. Give it references to all consuming job's BOs through v3d_job_reference_bos() instead of looking the handles up a second time; that avoids a redundant lookup and guarantees both jobs reference the exact same objects. As the CACHE_CLEAN job now carries a BO array as well, add a per-job `has_implicit_dep` flag so that only the consuming jobs take implicit dependencies. The CACHE_CLEAN job (a global flush) and the BIN job (binning waiting on another context is not a realistic scenario) are excluded.
Title drm/v3d: Associate BOs with every job that accesses them
First Time appeared Linux
Linux linux Kernel
CPEs cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*
Vendors & Products Linux
Linux linux Kernel
References

Subscriptions

Linux Linux Kernel
cve-icon MITRE

Status: PUBLISHED

Assigner: Linux

Published:

Updated: 2026-09-17T16:10:38.350Z

Reserved: 2026-09-17T15:57:05.658Z

Link: CVE-2026-93047

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Received

Published: 2026-09-17T17:17:57.977

Modified: 2026-09-17T17:17:57.977

Link: CVE-2026-93047

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-19T12:45:16Z

Weaknesses
  • CWE-362

    Concurrent Execution using Shared Resource with Improper Synchronization ('Race Condition')