CVE-2026-68261

Source
https://cve.org/CVERecord?id=CVE-2026-68261
Import Source
https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-68261.json
JSON Data
https://api.osv.dev/v1/vulns/CVE-2026-68261
Downstream
Published
2026-08-10T12:01:35.600Z
Modified
2026-08-12T04:18:47.299310047Z
Summary
drm/imagination: fix error checking of pvr_vm_context_lookup()
Details

In the Linux kernel, the following vulnerability has been resolved:

drm/imagination: fix error checking of pvrvmcontext_lookup()

Since pvrvmcontextlookup() returns either NULL or a pointer, then stop using ISERR() for checking the return value.

Using ISERR() leads to the kernel oops reported below. It can be reproduced by passing an invalid VM context handle from userspace to the DRMIOCTLPVRCREATE_CONTEXT ioctl.

[ 92.733119] Unable to handle kernel NULL pointer dereference at virtual address 0000000000000148 [ 92.742042] Mem abort info: [ 92.744890] ESR = 0x0000000096000004 [ 92.748686] EC = 0x25: DABT (current EL), IL = 32 bits [ 92.754020] SET = 0, FnV = 0 [ 92.757154] EA = 0, S1PTW = 0 [ 92.760337] FSC = 0x04: level 0 translation fault [ 92.765243] Data abort info: [ 92.768129] ISV = 0, ISS = 0x00000004, ISS2 = 0x00000000 [ 92.773626] CM = 0, WnR = 0, TnD = 0, TagAccess = 0 [ 92.778763] GCS = 0, Overlay = 0, DirtyBit = 0, Xs = 0 [ 92.784098] user pgtable: 4k pages, 48-bit VAs, pgdp=000000088ed23000 [ 92.790550] [0000000000000148] pgd=0000000000000000, p4d=0000000000000000 [ 92.797381] Internal error: Oops: 0000000096000004 [#1] SMP [ 92.803027] Modules linked in: powervr [ 92.852533] CPU: 0 UID: 0 PID: 409 Comm: triangle Not tainted 7.1.0-rc5-g98b46e693b91 #1 PREEMPT [ 92.861385] Hardware name: Texas Instruments AM68 SK (DT) [ 92.866766] pstate: 60000005 (nZCv daif -PAN -UAO -TCO -DIT -SSBS BTYPE=--) [ 92.873709] pc : pvrvmgetfwmemcontext+0x0/0xc [powervr] [ 92.879376] lr : pvrqueuecreate+0x26c/0x440 [powervr] [ 92.884595] sp : ffff8000837fbb00 [ 92.887895] x29: ffff8000837fbb60 x28: 0000000000000000 x27: ffff8000837fbce8 [ 92.895015] x26: ffff000807f61a40 x25: ffff000807f61a00 x24: ffff000807f64400 [ 92.902135] x23: ffff00080a5ab000 x22: ffff800079b24730 x21: ffff000807f61800 [ 92.909254] x20: ffff00080999e680 x19: 0000000000000000 x18: 0000000000000000 [ 92.916373] x17: 0000000000000000 x16: 0000000000000000 x15: 0000000000000001 [ 92.923492] x14: 0000000000000000 x13: 0000000000000002 x12: ffff80008145b298 [ 92.930611] x11: ffff8000844e5000 x10: ffff80008165a130 x9 : 0000000000000100 [ 92.937730] x8 : 0000000000000001 x7 : ffff0008076b27e0 x6 : ffff00080ec43b7c [ 92.944850] x5 : ffff00080ec43b78 x4 : 0000000000000000 x3 : ffff00080999e680 [ 92.951968] x2 : 0000000000000000 x1 : 0000000000000000 x0 : 0000000000000000 [ 92.959088] Call trace: [ 92.961521] pvrvmgetfwmemcontext+0x0/0xc [powervr] (P) [ 92.967173] pvrcontextcreate+0x190/0x410 [powervr] [ 92.972218] pvrioctlcreatecontext+0x44/0x8c [powervr] [ 92.977608] drmioctlkernel+0xbc/0x124 [drm] [ 92.982127] drmioctl+0x1f8/0x4dc [drm] [ 92.986098] _arm64sysioctl+0xac/0x104 [ 92.990102] invokesyscall+0x54/0x10c [ 92.993842] el0svccommon.constprop.0+0x40/0xe0 [ 92.998532] doel0svc+0x1c/0x28 [ 93.001835] el0svc+0x38/0x11c [ 93.004969] el0t64synchandler+0xa0/0xe4 [ 93.009139] el0t64sync+0x198/0x19c [ 93.012792] Code: aa1703e0 d2800014 95cb0ba4 17ffffe8 (f940a400) [ 93.018869] ---[ end trace 0000000000000000 ]---

Database specific
{
    "osv_generated_from": "https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/68xxx/CVE-2026-68261.json",
    "cna_assigner": "Linux"
}
References

Affected packages

Git / git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git

Affected ranges

Type
GIT
Repo
https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git
Events
Introduced
d2d79d29bb98a32c511f7339a8e93b47544fdeac
Fixed
ce97192087c659f2e0c0c2a627330c7edcc9eeb3
Fixed
c45fafa69fe3f79e319369cf665da89868e3ef98
Fixed
401fbe3b6bbb6c94c24ee8843b7beed5111491ac
Fixed
cf385cf6e713eba0720651174dac0b2d2f5bb8f8

Database specific

source
"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-68261.json"

Linux / Kernel

Package

Name
Kernel

Affected ranges

Type
ECOSYSTEM
Events
Introduced
6.8.0
Fixed
6.12.101
Type
ECOSYSTEM
Events
Introduced
6.13.0
Fixed
6.18.42
Type
ECOSYSTEM
Events
Introduced
6.19.0
Fixed
7.1.6

Database specific

source
"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-68261.json"