CVE-2026-100077

Source
https://cve.org/CVERecord?id=CVE-2026-100077
Import Source
https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-100077.json
JSON Data
https://api.osv.dev/v1/vulns/CVE-2026-100077
Downstream
Published
2026-09-25T13:06:48Z
Modified
2026-09-27T03:47:23Z
Summary
drm/msm: Recover HW before retire hung submit
Details

In the Linux kernel, the following vulnerability has been resolved:

drm/msm: Recover HW before retire hung submit

During recovery, it is not safe to retire the hung submit before we recover the GPU. Retiring the submit triggers BO free and that can result in GPU pagefaults since the GPU may be actively accessing those BOs.

To fix this, retire the submits after gpu recovery is complete in recover_worker().

Patchwork: https://patchwork.freedesktop.org/patch/730655/

Database specific
{
    "cna_assigner":  "Linux",
    "osv_generated_from":  "https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/100xxx/CVE-2026-100077.json"
}
References

Affected packages

Git / git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git

Affected ranges

Type
GIT
Repo
https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git
Events
Introduced
1a370be9ac51129e40b0ed7fa71d2b2b92bc47e5
Fixed
e36284257eeca13768687bf8e52f66f8ea0e8794
Fixed
dc64cf9d71428234389b635d142cb5fe07d57eab
Fixed
b303e1d52811de7d1bcf793560754d4df68d4a1c

Database specific

source
"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-100077.json"

Linux / Kernel

Package

Name
Kernel

Affected ranges

Type
ECOSYSTEM
Events
Introduced
4.2.0
Fixed
6.18.52
Type
ECOSYSTEM
Events
Introduced
6.19.0
Fixed
7.2.6

Database specific

source
"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-100077.json"