Impact
The DRM v3d driver assigns a job to queue->active_job before attempting to create a fence. If fence creation fails, the callback returns NULL without clearing the active_job pointer, leaving a dangling reference in the queue structure. This use‑after‑free flaw can cause the kernel to dereference a stale pointer, leading to a crash. Kernel code execution is inferred from the described scenario but is not explicitly stated in the CVE description. The vulnerability arises from improper error handling during job submission.
Affected Systems
All Linux kernel versions that include the DRM v3d driver and have not yet applied the fix that clears queue->active_job on fence‑creation failure. Because the driver is part of the core kernel, any distribution with the v3d module loaded before the patch is affected.
Risk and Exploitability
The CVSS score of 7.8 classifies this as high severity, while the EPSS score of less than 1% indicates a low likelihood of exploitation in typical environments. The vulnerability is not listed in CISA’s KEV catalog. Based on the description, it is inferred that the likely attack vector is local; an attacker would need to trigger a job submission that results in a fence creation failure, which may require privileged or user control over GPU workloads.
OpenCVE Enrichment
Debian DLA
Debian DSA