Impact
A race condition has been discovered in the Linux kernel DRM V3D driver where buffer objects (BOs) are only attached to the last job in a chain of jobs. The consuming job—typically a rendering operation—ends up with an empty BO list, causing it to miss implicit dependencies. Consequently, the job may be dispatched to the hardware and read a BO that another context is still writing to, leading to data corruption. This flaw allows a malicious or malfunctioning job to produce corrupted graphics data or potentially exploit the corrupted state to gain higher privileges, although the exact impact depends on the kernel configuration and the attacker’s capabilities.
Affected Systems
This vulnerability affects all Linux kernel builds that include the DRM V3D driver prior to the application of the fix referenced in the commit logs. No specific kernel version range is enumerated, implying that any kernel containing the vulnerable driver is susceptible until the patch is integrated. The issue is limited to the V3D hardware abstraction within the DRM subsystem; other DRM drivers are not involved.
Risk and Exploitability
The EPSS score for this flaw is reported as less than 1%, indicating a low likelihood of exploitation. It is not listed in the CISA KEV catalog, suggesting no known exploited variants as of the latest data. The attack vector is inferred to be local or privileged, requiring access to submit DRM jobs that trigger the problematic job chain. With proper access control, the risk is moderate, but the potential for data corruption or privilege escalation warrants timely remediation.
OpenCVE Enrichment