CVE-2026-68437 (GCVE-0-2026-68437)
Vulnerability from cvelistv5
Published
2026-08-12 00:07
Modified
2026-08-17 05:05
Severity ?
Summary
In the Linux kernel, the following vulnerability has been resolved: drm/imagination: Fit paired fragment job in the correct CCCB For geometry jobs with a paired fragment job, at the moment, the DRM scheduler's prepare_job() callback: - checks for internal (driver) dependencies for the geometry job; - calls into pvr_queue_get_paired_frag_job_dep() to check for external dependencies for the fragment job (the two jobs are submitted together but the common scheduler code doesn't know about it, so this needs to be done at this point in time); - calls into the prepare_job() callback again, but for the fragment job, to check its internal dependencies as well, passing the fragment job's drm_sched_job and the geometry job's drm_sched_entity / pvr_queue. The problem with the last step is that pvr_queue_prepare_job() doesn't always take the mismatched fragment job and geometry queue into account, in particular when checking whether there is space for the fragment command to be submitted, so the code ends up checking for space in the geometry (i.e. wrong) CCCB. The rest of the nested prepare_job() callback happens to work fine at the moment as the other internal dependencies are not relevant for a paired fragment job. Move the initialisation of a paired fragment job's done fence and CCCB fence to pvr_queue_get_paired_frag_job_dep(), inferring the correct queue from the fragment job itself. This fixes cases where prepare_job() wrongly assumed that there was enough space for a paired fragment job in its own CCCB, unblocking run_job(), which then returned early without writing the full sequence of commands to the CCCB. The above lead to kernel warnings such as the following and potentially job timeouts (depending on waiters on the missing commands): [ 552.421075] WARNING: drivers/gpu/drm/imagination/pvr_cccb.c:178 at pvr_cccb_write_command_with_header+0x2c4/0x330 [powervr], CPU#2: kworker/u16:5/63 [ 552.421230] Modules linked in: [ 552.421592] CPU: 2 UID: 0 PID: 63 Comm: kworker/u16:5 Tainted: G W 7.0.0-rc2-gc5d053e4dccb #39 PREEMPT [ 552.421625] Tainted: [W]=WARN [ 552.421637] Hardware name: Texas Instruments AM625 SK (DT) [ 552.421655] Workqueue: powervr-sched drm_sched_run_job_work [gpu_sched] [ 552.421744] pstate: 80000005 (Nzcv daif -PAN -UAO -TCO -DIT -SSBS BTYPE=--) [ 552.421766] pc : pvr_cccb_write_command_with_header+0x2c4/0x330 [powervr] [ 552.421850] lr : pvr_queue_submit_job_to_cccb+0x57c/0xa74 [powervr] [ 552.421923] sp : ffff800084c47650 [ 552.421936] x29: ffff800084c47740 x28: 0000000000000df8 x27: ffff800088a77000 [ 552.421979] x26: 0000000000000030 x25: ffff800084c47680 x24: 0000000000001000 [ 552.422017] x23: ffff800084c47820 x22: 1ffff00010988ecc x21: 0000000000000008 [ 552.422055] x20: 0000000000000208 x19: ffff000006ad5a88 x18: 0000000000000000 [ 552.422093] x17: 0000000020020000 x16: 0000000000020000 x15: 0000000000000000 [ 552.422130] x14: 0000000000000000 x13: 0000000000000000 x12: 0000000000000000 [ 552.422167] x11: 000000000000f2f2 x10: 00000000f3000000 x9 : 00000000f3f3f3f3 [ 552.422204] x8 : 00000000f2f2f200 x7 : ffff700010988ecc x6 : 0000000000000008 [ 552.422241] x5 : 0000000000000000 x4 : 1ffff0001114ee00 x3 : 0000000000000000 [ 552.422278] x2 : 0000000000000007 x1 : 0000000000000fff x0 : 000000000000002f [ 552.422316] Call trace: [ 552.422330] pvr_cccb_write_command_with_header+0x2c4/0x330 [powervr] (P) [ 552.422411] pvr_queue_submit_job_to_cccb+0x57c/0xa74 [powervr] [ 552.422486] pvr_queue_run_job+0x3a4/0x990 [powervr] [ 552.422562] drm_sched_run_job_work+0x580/0xd48 [gpu_sched] [ 552.422623] process_one_work+0x520/0x1288 [ 552.422657] worker_thread+0x3f0/0xb3c [ 552.422679] kthread+0x334/0x3d8 [ 552.422706] ret_from_fork+0x10/0x20
Impacted products
Vendor Product Version
Linux Linux Version: eaf01ee5ba28b97f96a3d3eec4c5fbfb37ee4cde
Version: eaf01ee5ba28b97f96a3d3eec4c5fbfb37ee4cde
Version: eaf01ee5ba28b97f96a3d3eec4c5fbfb37ee4cde
Version: eaf01ee5ba28b97f96a3d3eec4c5fbfb37ee4cde
Create a notification for this product.
Show details on NVD website


{
  "containers": {
    "cna": {
      "affected": [
        {
          "defaultStatus": "unaffected",
          "product": "Linux",
          "programFiles": [
            "drivers/gpu/drm/imagination/pvr_queue.c"
          ],
          "repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
          "vendor": "Linux",
          "versions": [
            {
              "lessThan": "15a9863929206911a08b6f62de9c5da6931dbc9e",
              "status": "affected",
              "version": "eaf01ee5ba28b97f96a3d3eec4c5fbfb37ee4cde",
              "versionType": "git"
            },
            {
              "lessThan": "e2c29d51c0f65459ae5bbf7ccc302df4c359c473",
              "status": "affected",
              "version": "eaf01ee5ba28b97f96a3d3eec4c5fbfb37ee4cde",
              "versionType": "git"
            },
            {
              "lessThan": "4ddf82c18ee4b3d14ec7fa002c4039b46c961abc",
              "status": "affected",
              "version": "eaf01ee5ba28b97f96a3d3eec4c5fbfb37ee4cde",
              "versionType": "git"
            },
            {
              "lessThan": "4baf9e70cb756d78dd56419f8baee2978a72d0c3",
              "status": "affected",
              "version": "eaf01ee5ba28b97f96a3d3eec4c5fbfb37ee4cde",
              "versionType": "git"
            }
          ]
        },
        {
          "defaultStatus": "affected",
          "product": "Linux",
          "programFiles": [
            "drivers/gpu/drm/imagination/pvr_queue.c"
          ],
          "repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
          "vendor": "Linux",
          "versions": [
            {
              "status": "affected",
              "version": "6.8"
            },
            {
              "lessThan": "6.8",
              "status": "unaffected",
              "version": "0",
              "versionType": "semver"
            },
            {
              "lessThanOrEqual": "6.12.*",
              "status": "unaffected",
              "version": "6.12.101",
              "versionType": "semver"
            },
            {
              "lessThanOrEqual": "6.18.*",
              "status": "unaffected",
              "version": "6.18.42",
              "versionType": "semver"
            },
            {
              "lessThanOrEqual": "7.1.*",
              "status": "unaffected",
              "version": "7.1.6",
              "versionType": "semver"
            },
            {
              "lessThanOrEqual": "*",
              "status": "unaffected",
              "version": "7.2",
              "versionType": "original_commit_for_fix"
            }
          ]
        }
      ],
      "cpeApplicability": [
        {
          "nodes": [
            {
              "cpeMatch": [
                {
                  "criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
                  "versionEndExcluding": "6.12.101",
                  "versionStartIncluding": "6.8",
                  "vulnerable": true
                },
                {
                  "criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
                  "versionEndExcluding": "6.18.42",
                  "versionStartIncluding": "6.8",
                  "vulnerable": true
                },
                {
                  "criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
                  "versionEndExcluding": "7.1.6",
                  "versionStartIncluding": "6.8",
                  "vulnerable": true
                },
                {
                  "criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
                  "versionEndExcluding": "7.2",
                  "versionStartIncluding": "6.8",
                  "vulnerable": true
                }
              ],
              "negate": false,
              "operator": "OR"
            }
          ]
        }
      ],
      "descriptions": [
        {
          "lang": "en",
          "value": "In the Linux kernel, the following vulnerability has been resolved:\n\ndrm/imagination: Fit paired fragment job in the correct CCCB\n\nFor geometry jobs with a paired fragment job, at the moment, the\nDRM scheduler\u0027s prepare_job() callback:\n\n- checks for internal (driver) dependencies for the geometry job;\n- calls into pvr_queue_get_paired_frag_job_dep() to check for external\n  dependencies for the fragment job (the two jobs are submitted together\n  but the common scheduler code doesn\u0027t know about it, so this needs to\n  be done at this point in time);\n- calls into the prepare_job() callback again, but for the fragment job,\n  to check its internal dependencies as well, passing the fragment job\u0027s\n  drm_sched_job and the geometry job\u0027s drm_sched_entity / pvr_queue.\n\nThe problem with the last step is that pvr_queue_prepare_job() doesn\u0027t\nalways take the mismatched fragment job and geometry queue into account,\nin particular when checking whether there is space for the fragment\ncommand to be submitted, so the code ends up checking for space in the\ngeometry (i.e. wrong) CCCB.\nThe rest of the nested prepare_job() callback happens to work fine at\nthe moment as the other internal dependencies are not relevant for a\npaired fragment job.\n\nMove the initialisation of a paired fragment job\u0027s done fence and CCCB\nfence to pvr_queue_get_paired_frag_job_dep(), inferring the correct\nqueue from the fragment job itself.\n\nThis fixes cases where prepare_job() wrongly assumed that there was\nenough space for a paired fragment job in its own CCCB, unblocking\nrun_job(), which then returned early without writing the full sequence\nof commands to the CCCB.\n\nThe above lead to kernel warnings such as the following and potentially\njob timeouts (depending on waiters on the missing commands):\n\n  [  552.421075] WARNING: drivers/gpu/drm/imagination/pvr_cccb.c:178 at pvr_cccb_write_command_with_header+0x2c4/0x330 [powervr], CPU#2: kworker/u16:5/63\n  [  552.421230] Modules linked in:\n  [  552.421592] CPU: 2 UID: 0 PID: 63 Comm: kworker/u16:5 Tainted: G        W           7.0.0-rc2-gc5d053e4dccb #39 PREEMPT\n  [  552.421625] Tainted: [W]=WARN\n  [  552.421637] Hardware name: Texas Instruments AM625 SK (DT)\n  [  552.421655] Workqueue: powervr-sched drm_sched_run_job_work [gpu_sched]\n  [  552.421744] pstate: 80000005 (Nzcv daif -PAN -UAO -TCO -DIT -SSBS BTYPE=--)\n  [  552.421766] pc : pvr_cccb_write_command_with_header+0x2c4/0x330 [powervr]\n  [  552.421850] lr : pvr_queue_submit_job_to_cccb+0x57c/0xa74 [powervr]\n  [  552.421923] sp : ffff800084c47650\n  [  552.421936] x29: ffff800084c47740 x28: 0000000000000df8 x27: ffff800088a77000\n  [  552.421979] x26: 0000000000000030 x25: ffff800084c47680 x24: 0000000000001000\n  [  552.422017] x23: ffff800084c47820 x22: 1ffff00010988ecc x21: 0000000000000008\n  [  552.422055] x20: 0000000000000208 x19: ffff000006ad5a88 x18: 0000000000000000\n  [  552.422093] x17: 0000000020020000 x16: 0000000000020000 x15: 0000000000000000\n  [  552.422130] x14: 0000000000000000 x13: 0000000000000000 x12: 0000000000000000\n  [  552.422167] x11: 000000000000f2f2 x10: 00000000f3000000 x9 : 00000000f3f3f3f3\n  [  552.422204] x8 : 00000000f2f2f200 x7 : ffff700010988ecc x6 : 0000000000000008\n  [  552.422241] x5 : 0000000000000000 x4 : 1ffff0001114ee00 x3 : 0000000000000000\n  [  552.422278] x2 : 0000000000000007 x1 : 0000000000000fff x0 : 000000000000002f\n  [  552.422316] Call trace:\n  [  552.422330]  pvr_cccb_write_command_with_header+0x2c4/0x330 [powervr] (P)\n  [  552.422411]  pvr_queue_submit_job_to_cccb+0x57c/0xa74 [powervr]\n  [  552.422486]  pvr_queue_run_job+0x3a4/0x990 [powervr]\n  [  552.422562]  drm_sched_run_job_work+0x580/0xd48 [gpu_sched]\n  [  552.422623]  process_one_work+0x520/0x1288\n  [  552.422657]  worker_thread+0x3f0/0xb3c\n  [  552.422679]  kthread+0x334/0x3d8\n  [  552.422706]  ret_from_fork+0x10/0x20"
        }
      ],
      "providerMetadata": {
        "dateUpdated": "2026-08-17T05:05:34.181Z",
        "orgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
        "shortName": "Linux"
      },
      "references": [
        {
          "url": "https://git.kernel.org/stable/c/15a9863929206911a08b6f62de9c5da6931dbc9e"
        },
        {
          "url": "https://git.kernel.org/stable/c/e2c29d51c0f65459ae5bbf7ccc302df4c359c473"
        },
        {
          "url": "https://git.kernel.org/stable/c/4ddf82c18ee4b3d14ec7fa002c4039b46c961abc"
        },
        {
          "url": "https://git.kernel.org/stable/c/4baf9e70cb756d78dd56419f8baee2978a72d0c3"
        }
      ],
      "title": "drm/imagination: Fit paired fragment job in the correct CCCB",
      "x_generator": {
        "engine": "bippy-1.2.0"
      }
    }
  },
  "cveMetadata": {
    "assignerOrgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
    "assignerShortName": "Linux",
    "cveId": "CVE-2026-68437",
    "datePublished": "2026-08-12T00:07:25.745Z",
    "dateReserved": "2026-07-30T09:28:09.394Z",
    "dateUpdated": "2026-08-17T05:05:34.181Z",
    "state": "PUBLISHED"
  },
  "dataType": "CVE_RECORD",
  "dataVersion": "5.2"
}


Log in or create an account to share your comment.




Tags
Taxonomy of the tags.


Loading…

Loading…

Loading…

Sightings

Author Source Type Date

Nomenclature

  • Seen: The vulnerability was mentioned, discussed, or seen somewhere by the user.
  • Confirmed: The vulnerability is confirmed from an analyst perspective.
  • Published Proof of Concept: A public proof of concept is available for this vulnerability.
  • Exploited: This vulnerability was exploited and seen by the user reporting the sighting.
  • Patched: This vulnerability was successfully patched by the user reporting the sighting.
  • Not exploited: This vulnerability was not exploited or seen by the user reporting the sighting.
  • Not confirmed: The user expresses doubt about the veracity of the vulnerability.
  • Not patched: This vulnerability was not successfully patched by the user reporting the sighting.


Loading…

Loading…