CVE-2026-53139: falha em Linux
drm/v3d: Skip CSD when it has zeroed workgroups
Publicada em · Atualizada em
3Vexday Risk Score
Sem sinal de exploração. Nenhum artefato público de exploração conhecido até agora.
ssvc Trackepss 0.1%
probabilidade de exploração
0.1%top 98% das CVEs
exploração observada
nãonenhuma fonte reporta
In the Linux kernel, the following vulnerability has been resolved:
drm/v3d: Skip CSD when it has zeroed workgroups
A compute shader dispatch encodes its workgroup counts in the CFG0..CFG2
registers. Kicking off a dispatch with a zero count in any of the three
dimensions is invalid. First, the hardware will process 0 as 65536,
while the user-space driver exposes a maximum of 65535. Over that, a
submission with a zeroed workgroup dimension should be a no-op.
These zeroed counts can reach the dispatch path through an indirect CSD
job, whose workgroup counts are only known once the indirect buffer is
read and may legitimately be zero, but such scenario should only result in
a no-op.
Overwrite the indirect CSD job workgroup counts with the indirect BO
ones, even if they are zeroed, and don't submit the job to the hardware
when any of the workgroup counts is zero, so the job completes immediately
instead of running the shader.
Produtos afetados
Linux · LinuxCVEs relacionadas — Linux
No mesmo produto, das mais perigosas para as menos.
CVE-2024-53197HIGHALSA: usb-audio: Fix potential out-of-bound accesses for Extigy and Mbox devicesEPSS 4.1%KEVCVE-2026-31431HIGHcrypto: algif_aead - Revert to operating out-of-placeEPSS 3.4%KEVCVE-2024-53104HIGHmedia: uvcvideo: Skip parsing frames of type UVC_VS_UNDEFINED in uvc_parse_formatEPSS 3.4%KEVCVE-2025-39682CRITICALtls: fix handling of zero-length records on the rx_listEPSS 2.9%KEVCVE-2024-36971HIGHnet: fix __dst_negative_advice() raceEPSS 2.7%KEVCVE-2024-53150HIGHALSA: usb-audio: Fix out of bounds reads when finding clock sourcesEPSS 1.4%KEV
Referências
https://git.kernel.org/stable/c/11e6432836394e00d39e468cd514f9ddb66f1e49https://git.kernel.org/stable/c/7f93fad5ea0affc9e1505dd0f7596c0fdb496213https://git.kernel.org/stable/c/8b51c5406ad748c3d5575b66b6009b5dbbc08b80https://git.kernel.org/stable/c/9655b56b6de918e1c22b92f3880ae41b052cbd00https://git.kernel.org/stable/c/abb069fdf51a9ddabcc1ed125dafe54e2089900bhttps://git.kernel.org/stable/c/ad166139d123dc162e8636f0c7962516d04074e1https://git.kernel.org/stable/c/b3a8dd72b0d008ff142880b4dbe5ca37dcf962b4