CVE-2026-53139

Severity CVSS v4.0:
Pending analysis
Type:
Unavailable / Other
Publication date:
25/06/2026
Last modified:
06/07/2026

Description

In the Linux kernel, the following vulnerability has been resolved:<br /> <br /> drm/v3d: Skip CSD when it has zeroed workgroups<br /> <br /> A compute shader dispatch encodes its workgroup counts in the CFG0..CFG2<br /> registers. Kicking off a dispatch with a zero count in any of the three<br /> dimensions is invalid. First, the hardware will process 0 as 65536,<br /> while the user-space driver exposes a maximum of 65535. Over that, a<br /> submission with a zeroed workgroup dimension should be a no-op.<br /> <br /> These zeroed counts can reach the dispatch path through an indirect CSD<br /> job, whose workgroup counts are only known once the indirect buffer is<br /> read and may legitimately be zero, but such scenario should only result in<br /> a no-op.<br /> <br /> Overwrite the indirect CSD job workgroup counts with the indirect BO<br /> ones, even if they are zeroed, and don&amp;#39;t submit the job to the hardware<br /> when any of the workgroup counts is zero, so the job completes immediately<br /> instead of running the shader.

Vulnerable products and versions

CPE From Up to
cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:* 5.3 (including) 5.15.211 (excluding)
cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:* 5.16 (including) 6.1.177 (excluding)
cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:* 6.2 (including) 6.6.144 (excluding)
cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:* 6.7 (including) 6.12.95 (excluding)
cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:* 6.13 (including) 6.18.36 (excluding)
cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:* 6.19 (including) 7.0.13 (excluding)
cpe:2.3:o:linux:linux_kernel:7.1:rc1:*:*:*:*:*:*
cpe:2.3:o:linux:linux_kernel:7.1:rc2:*:*:*:*:*:*
cpe:2.3:o:linux:linux_kernel:7.1:rc3:*:*:*:*:*:*
cpe:2.3:o:linux:linux_kernel:7.1:rc4:*:*:*:*:*:*
cpe:2.3:o:linux:linux_kernel:7.1:rc5:*:*:*:*:*:*
cpe:2.3:o:linux:linux_kernel:7.1:rc6:*:*:*:*:*:*