Description
In the Linux kernel, the following vulnerability has been resolved:

drm/v3d: Clear queue->active_job when v3d_fence_create() fails

The run_job() callbacks for BIN, RENDER, TFU and CSD assign the incoming
job to queue->active_job before calling v3d_fence_create(). If
v3d_fence_create() fails, the callback returns NULL without clearing
active_job, leaving a dangling pointer.

Create a failure path in all run_job() callbacks that clears the active
job before returning NULL. The BIN path takes queue->queue_lock around the
clear as it races against v3d_overflow_mem_work(); RENDER, TFU and CSD
paths have no concurrent reader, so the clear is lock-free.
Published: 2026-09-17
Score: 7.8 High
EPSS: < 1% Very Low
KEV: No
Impact: Use‑After‑Free that may cause a kernel crash; privilege escalation is inferred.
Action: Patch Now
AI Analysis

Impact

The DRM v3d driver assigns a job to queue->active_job before attempting to create a fence. If fence creation fails, the callback returns NULL without clearing the active_job pointer, leaving a dangling reference in the queue structure. This use‑after‑free flaw can cause the kernel to dereference a stale pointer, leading to a crash. Kernel code execution is inferred from the described scenario but is not explicitly stated in the CVE description. The vulnerability arises from improper error handling during job submission.

Affected Systems

All Linux kernel versions that include the DRM v3d driver and have not yet applied the fix that clears queue->active_job on fence‑creation failure. Because the driver is part of the core kernel, any distribution with the v3d module loaded before the patch is affected.

Risk and Exploitability

The CVSS score of 7.8 classifies this as high severity, while the EPSS score of less than 1% indicates a low likelihood of exploitation in typical environments. The vulnerability is not listed in CISA’s KEV catalog. Based on the description, it is inferred that the likely attack vector is local; an attacker would need to trigger a job submission that results in a fence creation failure, which may require privileged or user control over GPU workloads.

Generated by OpenCVE AI on September 19, 2026 at 22:22 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Upgrade the Linux kernel to a release containing the patched v3d driver that clears queue->active_job on fence‑creation failure.
  • If an immediate kernel upgrade is not feasible, unload or disable the drm_v3d module on affected hosts until the patch is applied.
  • Enable kernel package signing verification and monitor kernel update repositories for new releases that address this issue.

Generated by OpenCVE AI on September 19, 2026 at 22:22 UTC.

Tracking

Sign in to view the affected projects.

Advisories
Source ID Title
Debian DLA Debian DLA DLA-4817-1 linux-6.12 security update
Debian DSA Debian DSA DSA-6528-1 linux security update
History

Sat, 19 Sep 2026 23:00:00 +0000

Type Values Removed Values Added
Weaknesses CWE-416

Sat, 19 Sep 2026 20:15:00 +0000

Type Values Removed Values Added
Weaknesses CWE-416

Sat, 19 Sep 2026 09:45:00 +0000

Type Values Removed Values Added
Weaknesses CWE-416

Fri, 18 Sep 2026 21:30:00 +0000

Type Values Removed Values Added
Metrics cvssV3_1

{'score': 7.8, 'vector': 'CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H'}


Thu, 17 Sep 2026 16:30:00 +0000

Type Values Removed Values Added
Description In the Linux kernel, the following vulnerability has been resolved: drm/v3d: Clear queue->active_job when v3d_fence_create() fails The run_job() callbacks for BIN, RENDER, TFU and CSD assign the incoming job to queue->active_job before calling v3d_fence_create(). If v3d_fence_create() fails, the callback returns NULL without clearing active_job, leaving a dangling pointer. Create a failure path in all run_job() callbacks that clears the active job before returning NULL. The BIN path takes queue->queue_lock around the clear as it races against v3d_overflow_mem_work(); RENDER, TFU and CSD paths have no concurrent reader, so the clear is lock-free.
Title drm/v3d: Clear queue->active_job when v3d_fence_create() fails
First Time appeared Linux
Linux linux Kernel
CPEs cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*
Vendors & Products Linux
Linux linux Kernel
References

Subscriptions

Linux Linux Kernel
cve-icon MITRE

Status: PUBLISHED

Assigner: Linux

Published:

Updated: 2026-09-18T17:56:28.889Z

Reserved: 2026-09-17T16:02:15.092Z

Link: CVE-2026-93192

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Received

Published: 2026-09-17T17:18:15.447

Modified: 2026-09-18T18:18:24.610

Link: CVE-2026-93192

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-19T22:45:06Z

Weaknesses