Instituto Nacional de ciberseguridad. Sección Incibe
Instituto Nacional de Ciberseguridad. Sección INCIBE-CERT

CVE-2026-68281

Gravedad:
Pendiente de análisis
Tipo:
No Disponible / Otro tipo
Fecha de publicación:
10/08/2026
Última modificación:
17/08/2026

Descripción

*** Pendiente de traducción *** In the Linux kernel, the following vulnerability has been resolved:<br /> <br /> drm/imagination: Count paired job fence as dependency in prepare_job()<br /> <br /> The DRM scheduler&amp;#39;s prepare_job() callback counts the remaining<br /> non-signaled native dependencies for a job, preventing job submission<br /> until those (plus job data and fence update) can fit in the job queue&amp;#39;s<br /> CCCB.<br /> <br /> This means checking which dependencies can be waited upon in the<br /> firmware, i.e. whether they are backed by a UFO object, i.e. whether<br /> their drm_sched_fence::parent has been assigned to a<br /> pvr_queue_fence::base fence. That happens when the job owning the fence<br /> is submitted to the firmware.<br /> <br /> Paired geometry and fragment jobs are submitted at the same time, which<br /> means the dependency between them can&amp;#39;t be checked this way before<br /> submission.<br /> <br /> Update job_count_remaining_native_deps() to take into account the<br /> dependency between paired jobs.<br /> <br /> This fixes cases where prepare_job() underestimated the space left in<br /> an almost full fragment CCCB, wrongly unblocking run_job(), which then<br /> returned early without writing the full sequence of commands to the<br /> CCCB.<br /> <br /> The above lead to kernel warnings such as the following and potentially<br /> job timeouts (depending on waiters on the missing commands):<br /> <br /> [ 375.702979] WARNING: drivers/gpu/drm/imagination/pvr_cccb.c:178 at pvr_cccb_write_command_with_header+0x2c4/0x330 [powervr], CPU#1: kworker/u16:3/47<br /> [ 375.703160] Modules linked in:<br /> [ 375.703571] CPU: 1 UID: 0 PID: 47 Comm: kworker/u16:3 Tainted: G W 7.0.0-rc2-g817eb6b11ad5 #40 PREEMPT<br /> [ 375.703613] Tainted: [W]=WARN<br /> [ 375.703627] Hardware name: Texas Instruments AM625 SK (DT)<br /> [ 375.703645] Workqueue: powervr-sched drm_sched_run_job_work [gpu_sched]<br /> [ 375.703741] pstate: 80000005 (Nzcv daif -PAN -UAO -TCO -DIT -SSBS BTYPE=--)<br /> [ 375.703764] pc : pvr_cccb_write_command_with_header+0x2c4/0x330 [powervr]<br /> [ 375.703847] lr : pvr_queue_submit_job_to_cccb+0x578/0xa70 [powervr]<br /> [ 375.703921] sp : ffff800084a97650<br /> [ 375.703934] x29: ffff800084a97740 x28: 0000000000000958 x27: ffff80008565d000<br /> [ 375.703979] x26: 0000000000000030 x25: ffff800084a97680 x24: 0000000000001000<br /> [ 375.704017] x23: ffff800084a97820 x22: 1ffff00010952ecc x21: 0000000000000008<br /> [ 375.704056] x20: 00000000000006a8 x19: ffff00002ff7da88 x18: 0000000000000000<br /> [ 375.704093] x17: 0000000020020000 x16: 0000000000020000 x15: 0000000000000000<br /> [ 375.704132] x14: 0000000000000000 x13: 0000000000000000 x12: 0000000000000000<br /> [ 375.704168] x11: 000000000000f2f2 x10: 00000000f3000000 x9 : 00000000f3f3f3f3<br /> [ 375.704206] x8 : 00000000f2f2f200 x7 : ffff700010952ecc x6 : 0000000000000008<br /> [ 375.704243] x5 : 0000000000000000 x4 : 1ffff00010acba00 x3 : 0000000000000000<br /> [ 375.704279] x2 : 0000000000000007 x1 : 0000000000000fff x0 : 000000000000002f<br /> [ 375.704317] Call trace:<br /> [ 375.704331] pvr_cccb_write_command_with_header+0x2c4/0x330 [powervr] (P)<br /> [ 375.704411] pvr_queue_submit_job_to_cccb+0x578/0xa70 [powervr]<br /> [ 375.704487] pvr_queue_run_job+0x3a4/0x990 [powervr]<br /> [ 375.704562] drm_sched_run_job_work+0x580/0xd48 [gpu_sched]<br /> [ 375.704623] process_one_work+0x520/0x1288<br /> [ 375.704658] worker_thread+0x3f0/0xb3c<br /> [ 375.704680] kthread+0x334/0x3d8<br /> [ 375.704706] ret_from_fork+0x10/0x20<br /> [ 375.704736] ---[ end trace 0000000000000000 ]---

Impacto