In the Linux kernel, the following vulnerability has been resolved:
drm/imagination: Fit paired fragment job in the correct CCCB
For geometry jobs with a paired fragment job, at the moment, the DRM scheduler's prepare_job() callback:
The problem with the last step is that pvrqueuepreparejob() doesn't always take the mismatched fragment job and geometry queue into account, in particular when checking whether there is space for the fragment command to be submitted, so the code ends up checking for space in the geometry (i.e. wrong) CCCB. The rest of the nested preparejob() callback happens to work fine at the moment as the other internal dependencies are not relevant for a paired fragment job.
Move the initialisation of a paired fragment job's done fence and CCCB fence to pvrqueuegetpairedfragjobdep(), inferring the correct queue from the fragment job itself.
This fixes cases where preparejob() wrongly assumed that there was enough space for a paired fragment job in its own CCCB, unblocking runjob(), which then returned early without writing the full sequence of commands to the CCCB.
The above lead to kernel warnings such as the following and potentially job timeouts (depending on waiters on the missing commands):
[ 552.421075] WARNING: drivers/gpu/drm/imagination/pvrcccb.c:178 at pvrcccbwritecommandwithheader+0x2c4/0x330 [powervr], CPU#2: kworker/u16:5/63 [ 552.421230] Modules linked in: [ 552.421592] CPU: 2 UID: 0 PID: 63 Comm: kworker/u16:5 Tainted: G W 7.0.0-rc2-gc5d053e4dccb #39 PREEMPT [ 552.421625] Tainted: [W]=WARN [ 552.421637] Hardware name: Texas Instruments AM625 SK (DT) [ 552.421655] Workqueue: powervr-sched drmschedrunjobwork [gpusched] [ 552.421744] pstate: 80000005 (Nzcv daif -PAN -UAO -TCO -DIT -SSBS BTYPE=--) [ 552.421766] pc : pvrcccbwritecommandwithheader+0x2c4/0x330 [powervr] [ 552.421850] lr : pvrqueuesubmitjobtocccb+0x57c/0xa74 [powervr] [ 552.421923] sp : ffff800084c47650 [ 552.421936] x29: ffff800084c47740 x28: 0000000000000df8 x27: ffff800088a77000 [ 552.421979] x26: 0000000000000030 x25: ffff800084c47680 x24: 0000000000001000 [ 552.422017] x23: ffff800084c47820 x22: 1ffff00010988ecc x21: 0000000000000008 [ 552.422055] x20: 0000000000000208 x19: ffff000006ad5a88 x18: 0000000000000000 [ 552.422093] x17: 0000000020020000 x16: 0000000000020000 x15: 0000000000000000 [ 552.422130] x14: 0000000000000000 x13: 0000000000000000 x12: 0000000000000000 [ 552.422167] x11: 000000000000f2f2 x10: 00000000f3000000 x9 : 00000000f3f3f3f3 [ 552.422204] x8 : 00000000f2f2f200 x7 : ffff700010988ecc x6 : 0000000000000008 [ 552.422241] x5 : 0000000000000000 x4 : 1ffff0001114ee00 x3 : 0000000000000000 [ 552.422278] x2 : 0000000000000007 x1 : 0000000000000fff x0 : 000000000000002f [ 552.422316] Call trace: [ 552.422330] pvrcccbwritecommandwithheader+0x2c4/0x330 [powervr] (P) [ 552.422411] pvrqueuesubmitjobtocccb+0x57c/0xa74 [powervr] [ 552.422486] pvrqueuerunjob+0x3a4/0x990 [powervr] [ 552.422562] drmschedrunjobwork+0x580/0xd48 [gpusched] [ 552.422623] processonework+0x520/0x1288 [ 552.422657] workerthread+0x3f0/0xb3c [ 552.422679] kthread+0x334/0x3d8 [ 552.422706] retfromfork+0x10/0x20
{
"osv_generated_from": "https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/68xxx/CVE-2026-68437.json",
"cna_assigner": "Linux"
}