CVE-2026-68281
Gravedad:
Pendiente de análisis
Tipo:
No Disponible / Otro tipo
Fecha de publicación:
10/08/2026
Última modificación:
17/08/2026
Descripción
*** Pendiente de traducción *** In the Linux kernel, the following vulnerability has been resolved:<br />
<br />
drm/imagination: Count paired job fence as dependency in prepare_job()<br />
<br />
The DRM scheduler&#39;s prepare_job() callback counts the remaining<br />
non-signaled native dependencies for a job, preventing job submission<br />
until those (plus job data and fence update) can fit in the job queue&#39;s<br />
CCCB.<br />
<br />
This means checking which dependencies can be waited upon in the<br />
firmware, i.e. whether they are backed by a UFO object, i.e. whether<br />
their drm_sched_fence::parent has been assigned to a<br />
pvr_queue_fence::base fence. That happens when the job owning the fence<br />
is submitted to the firmware.<br />
<br />
Paired geometry and fragment jobs are submitted at the same time, which<br />
means the dependency between them can&#39;t be checked this way before<br />
submission.<br />
<br />
Update job_count_remaining_native_deps() to take into account the<br />
dependency between paired jobs.<br />
<br />
This fixes cases where prepare_job() underestimated the space left in<br />
an almost full fragment CCCB, wrongly unblocking run_job(), which then<br />
returned early without writing the full sequence of commands to the<br />
CCCB.<br />
<br />
The above lead to kernel warnings such as the following and potentially<br />
job timeouts (depending on waiters on the missing commands):<br />
<br />
[ 375.702979] WARNING: drivers/gpu/drm/imagination/pvr_cccb.c:178 at pvr_cccb_write_command_with_header+0x2c4/0x330 [powervr], CPU#1: kworker/u16:3/47<br />
[ 375.703160] Modules linked in:<br />
[ 375.703571] CPU: 1 UID: 0 PID: 47 Comm: kworker/u16:3 Tainted: G W 7.0.0-rc2-g817eb6b11ad5 #40 PREEMPT<br />
[ 375.703613] Tainted: [W]=WARN<br />
[ 375.703627] Hardware name: Texas Instruments AM625 SK (DT)<br />
[ 375.703645] Workqueue: powervr-sched drm_sched_run_job_work [gpu_sched]<br />
[ 375.703741] pstate: 80000005 (Nzcv daif -PAN -UAO -TCO -DIT -SSBS BTYPE=--)<br />
[ 375.703764] pc : pvr_cccb_write_command_with_header+0x2c4/0x330 [powervr]<br />
[ 375.703847] lr : pvr_queue_submit_job_to_cccb+0x578/0xa70 [powervr]<br />
[ 375.703921] sp : ffff800084a97650<br />
[ 375.703934] x29: ffff800084a97740 x28: 0000000000000958 x27: ffff80008565d000<br />
[ 375.703979] x26: 0000000000000030 x25: ffff800084a97680 x24: 0000000000001000<br />
[ 375.704017] x23: ffff800084a97820 x22: 1ffff00010952ecc x21: 0000000000000008<br />
[ 375.704056] x20: 00000000000006a8 x19: ffff00002ff7da88 x18: 0000000000000000<br />
[ 375.704093] x17: 0000000020020000 x16: 0000000000020000 x15: 0000000000000000<br />
[ 375.704132] x14: 0000000000000000 x13: 0000000000000000 x12: 0000000000000000<br />
[ 375.704168] x11: 000000000000f2f2 x10: 00000000f3000000 x9 : 00000000f3f3f3f3<br />
[ 375.704206] x8 : 00000000f2f2f200 x7 : ffff700010952ecc x6 : 0000000000000008<br />
[ 375.704243] x5 : 0000000000000000 x4 : 1ffff00010acba00 x3 : 0000000000000000<br />
[ 375.704279] x2 : 0000000000000007 x1 : 0000000000000fff x0 : 000000000000002f<br />
[ 375.704317] Call trace:<br />
[ 375.704331] pvr_cccb_write_command_with_header+0x2c4/0x330 [powervr] (P)<br />
[ 375.704411] pvr_queue_submit_job_to_cccb+0x578/0xa70 [powervr]<br />
[ 375.704487] pvr_queue_run_job+0x3a4/0x990 [powervr]<br />
[ 375.704562] drm_sched_run_job_work+0x580/0xd48 [gpu_sched]<br />
[ 375.704623] process_one_work+0x520/0x1288<br />
[ 375.704658] worker_thread+0x3f0/0xb3c<br />
[ 375.704680] kthread+0x334/0x3d8<br />
[ 375.704706] ret_from_fork+0x10/0x20<br />
[ 375.704736] ---[ end trace 0000000000000000 ]---



