{"dataType":"CVE_RECORD","dataVersion":"5.2","cveMetadata":{"cveId":"CVE-2026-93192","assignerOrgId":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","state":"PUBLISHED","assignerShortName":"Linux","dateReserved":"2026-09-17T16:02:15.092Z","datePublished":"2026-09-17T16:12:16.428Z","dateUpdated":"2026-09-18T17:56:28.889Z"},"containers":{"cna":{"providerMetadata":{"orgId":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","shortName":"Linux","dateUpdated":"2026-09-18T17:56:28.889Z"},"descriptions":[{"lang":"en","value":"In the Linux kernel, the following vulnerability has been resolved:\n\ndrm/v3d: Clear queue->active_job when v3d_fence_create() fails\n\nThe run_job() callbacks for BIN, RENDER, TFU and CSD assign the incoming\njob to queue->active_job before calling v3d_fence_create(). If\nv3d_fence_create() fails, the callback returns NULL without clearing\nactive_job, leaving a dangling pointer.\n\nCreate a failure path in all run_job() callbacks that clears the active\njob before returning NULL. The BIN path takes queue->queue_lock around the\nclear as it races against v3d_overflow_mem_work(); RENDER, TFU and CSD\npaths have no concurrent reader, so the clear is lock-free."}],"metrics":[{"cvssV3_1":{"version":"3.1","vectorString":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H","baseScore":7.8,"baseSeverity":"HIGH"},"scenarios":[{"lang":"en","value":"AV:L - The dangling queue->active_job is created in v3d_bin_job_run/v3d_render_job_run/v3d_tfu_job_run/v3d_csd_job_run after DRM_IOCTL_V3D_SUBMIT_CL (v3d_submit_cl_ioctl), DRM_IOCTL_V3D_SUBMIT_TFU, or DRM_IOCTL_V3D_SUBMIT_CSD on /dev/dri/renderD* queues a job through v3d_push_job; the trigger is that local ioctl, not a remote protocol message.\nAC:L - v3d_fence_create() fails only on kzalloc of struct v3d_fence; the attacker submits the job first so ioctl-time allocations succeed, then applies memory pressure so the scheduler worker hits GFP_KERNEL ENOMEM, and can also drive v3d_overflow_mem_work via a BCL that raises V3D_INT_OUTOMEM, controlling both the failure and the UAF consumer.\nPR:L - v3d_submit_cl_ioctl/v3d_submit_tfu_ioctl/v3d_submit_csd_ioctl are DRM_RENDER_ALLOW|DRM_AUTH with no capable() check; drm_ioctl_permit() treats render-node clients as authenticated, so an unprivileged Raspberry Pi/video-group user (or GPU-passthrough container) with /dev/dri/renderD* can reach the run_job callbacks.\nUI:N - The attacker opens the render node and issues their own SUBMIT_CL/SUBMIT_TFU/SUBMIT_CSD ioctls plus memory pressure; no other user must mount media, open a file, or otherwise interact.\nS:U - The use-after-free is of a host-kernel v3d_job left in queue->active_job and later used by v3d_overflow_mem_work/v3d_irq_signal_fence, which is local kernel heap corruption/privilege escalation, not a KVM/Xen escape or IOMMU/DMA boundary bypass.\nC:H - After drm_sched_job_done/v3d_sched_job_free kfree's the job, v3d_overflow_mem_work still reads bin_job->render and v3d_irq_signal_fence reads active_job->irq_fence and stats from the freed slab, so heap reuse of the v3d_job yields an arbitrary kernel read.\nI:H - v3d_overflow_mem_work does list_add_tail(&bo->unref_head, &bin_job->render->unref_list) through the freed job, so spraying a replacement v3d_bin_job with a chosen render pointer is an arbitrary list-write; v3d_job_update_stats() likewise writes into the freed object.\nA:H - Dereferencing the dangling queue->active_job in v3d_irq_signal_fence (IRQ context) or v3d_overflow_mem_work after v3d_job_free() oopses or panics the kernel, matching other v3d active-job UAFs that produced fatal exceptions in v3d_irq()."}]}],"affected":[{"product":"Linux","vendor":"Linux","defaultStatus":"unaffected","repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","programFiles":["drivers/gpu/drm/v3d/v3d_sched.c"],"versions":[{"version":"a783a09ee76d6259296dc6aeea2b6884fa526980","lessThan":"bdeb73d7312100e00c3e643ff233f09b6ec114aa","status":"affected","versionType":"git"},{"version":"a783a09ee76d6259296dc6aeea2b6884fa526980","lessThan":"3a8aa74859dd73eaa76c55eb74da708e56ef51c5","status":"affected","versionType":"git"},{"version":"a783a09ee76d6259296dc6aeea2b6884fa526980","lessThan":"0b9878aba5cf93bc2b55ba9eb807757ce3239bec","status":"affected","versionType":"git"},{"version":"a783a09ee76d6259296dc6aeea2b6884fa526980","lessThan":"25a1669907512e927fab9ad4d4fb74ff57f63cd9","status":"affected","versionType":"git"}]},{"product":"Linux","vendor":"Linux","defaultStatus":"affected","repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","programFiles":["drivers/gpu/drm/v3d/v3d_sched.c"],"versions":[{"version":"5.3","status":"affected"},{"version":"0","lessThan":"5.3","status":"unaffected","versionType":"semver"},{"version":"6.12.110","lessThanOrEqual":"6.12.*","status":"unaffected","versionType":"semver"},{"version":"6.18.52","lessThanOrEqual":"6.18.*","status":"unaffected","versionType":"semver"},{"version":"7.2.6","lessThanOrEqual":"7.2.*","status":"unaffected","versionType":"semver"},{"version":"7.3-rc1","lessThanOrEqual":"*","status":"unaffected","versionType":"original_commit_for_fix"}]}],"cpeApplicability":[{"nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*","versionStartIncluding":"5.3","versionEndExcluding":"6.12.110"},{"vulnerable":true,"criteria":"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*","versionStartIncluding":"5.3","versionEndExcluding":"6.18.52"},{"vulnerable":true,"criteria":"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*","versionStartIncluding":"5.3","versionEndExcluding":"7.2.6"},{"vulnerable":true,"criteria":"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*","versionStartIncluding":"5.3","versionEndExcluding":"7.3-rc1"}]}]}],"references":[{"url":"https://git.kernel.org/stable/c/bdeb73d7312100e00c3e643ff233f09b6ec114aa"},{"url":"https://git.kernel.org/stable/c/3a8aa74859dd73eaa76c55eb74da708e56ef51c5"},{"url":"https://git.kernel.org/stable/c/0b9878aba5cf93bc2b55ba9eb807757ce3239bec"},{"url":"https://git.kernel.org/stable/c/25a1669907512e927fab9ad4d4fb74ff57f63cd9"}],"title":"drm/v3d: Clear queue->active_job when v3d_fence_create() fails","x_generator":{"engine":"bippy-1.2.0"}}}}