Direct naar de inhoud
Kritieke cyberalerts voor jouw sector & systemen — direct in je inbox. Aanmelden →
CVE's Videos Dagbriefing

← Terug naar CVE-database

CVE-2026-53285

MEDIUM · 5.5 CVSS Gepubliceerd: CWE-617

Beschrijving NL

In de Linux kernel is de volgende kwetsbaarheid verholpen:

drm/amd/display: Wrap DCN32 fantoomvlak toewijzing in DC_run_WITH_PREEMPTION_ENABLED

[Waarom]
dcn32_validate_bandwidth() wraps dcn32_internal_validate_bw() met
DC_FP_START()/DC_FP_END(). In x86 non-RT neemt DC_FP_START fpregs_lock(),
die lokale softirq's uitschakelt. Het DML1-pad door dcn32_enable_phantom_plane() roept kvzalloc () aan om
~335 KiB toewijzen voor dc_plane_state. Dit activeert het vmalloc-pad,
die BUG_ON(in_interrupt()) aanroept omdat het wordt aangeroepen binnen de
FPU-enabled (softirq disabled) regio, wat leidt tot een kernelcrash. [Hoe]
Wikkel de dc_state_create_phantom_plane() oproep in met de
DC_run_WITH_PREEMPTION_ENABLED() macro om preemption mogelijk te maken tijdens
deze geheugentoewijzing. (kers geplukt uit commit 885ccbef7b94a8b38f69c4211c679021aa27ad11)

Origineel (Engels) tonen

In the Linux kernel, the following vulnerability has been resolved:

drm/amd/display: Wrap DCN32 phantom-plane allocation in DC_RUN_WITH_PREEMPTION_ENABLED

[Why]
dcn32_validate_bandwidth() wraps dcn32_internal_validate_bw() with
DC_FP_START()/DC_FP_END(). In x86 non-RT, DC_FP_START takes fpregs_lock(),
which disables local softirqs.

The DML1 path through dcn32_enable_phantom_plane() calls kvzalloc() to
allocate ~335 KiB for dc_plane_state. This triggers the vmalloc path,
which calls BUG_ON(in_interrupt()) because it's invoked within the
FPU-enabled (softirq disabled) region, leading to a kernel crash.

[How]
Wrap the dc_state_create_phantom_plane() call with the
DC_RUN_WITH_PREEMPTION_ENABLED() macro to allow preemption during
this memory allocation.

(cherry picked from commit 885ccbef7b94a8b38f69c4211c679021aa27ad11)

Vendors

Linux

Affected products

Linux Kernel

References