From mboxrd@z Thu Jan 1 00:00:00 1970 Received: from smtp.kernel.org (aws-us-west-2-korg-mail-alma10-1.taild15c8.ts.net [100.103.45.18]) (using TLSv1.2 with cipher ECDHE-RSA-AES256-GCM-SHA384 (256/256 bits)) (No client certificate requested) by smtp.subspace.kernel.org (Postfix) with ESMTPS id 89FE53CEB99 for ; Mon, 10 Aug 2026 12:08:03 +0000 (UTC) Authentication-Results: smtp.subspace.kernel.org; arc=none smtp.client-ip=100.103.45.18 ARC-Seal:i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1786363684; cv=none; b=jzq5NGN3D0yLdSxcZTZiJTUr30vcCnfIZtQ9vj4LS2+Dzk27uBd8yyW11rJ/hqvgK/oSbgERshwPjNhUONckbNrKIeL5Ktc/K2ZMXtGJSoprayJJfyMYbu0JxKlQmntfWaHDMQ99TdZp8TKzP2tfGqd3XYeSuYoCHOlinVCGawY= ARC-Message-Signature:i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1786363684; c=relaxed/simple; bh=BjfwzmQJePH5BEijjI9Wo5/2JG0k629SWsgWyfXtaHw=; h=From:To:Cc:Subject:Date:Message-ID:MIME-Version; b=aON9du35x8836lq2MZ3Rih7IgayMj2dML9elyC3cOUBGGTebc7Jsfdc/z+nDoNG8Wsg64P34tvL1dxkwT7mI8vYbMdd2XaFOQP2BLuvrOXCKpL2TKpqNxJRSmK7ncE/Y7XjnjwKyhGihsYBtXG7WB6d/hl493GILoqa5K17YBOU= ARC-Authentication-Results:i=1; smtp.subspace.kernel.org; dkim=pass (1024-bit key) header.d=linuxfoundation.org header.i=@linuxfoundation.org header.b=Xdlj+Onx; arc=none smtp.client-ip=100.103.45.18 Authentication-Results: smtp.subspace.kernel.org; dkim=pass (1024-bit key) header.d=linuxfoundation.org header.i=@linuxfoundation.org header.b="Xdlj+Onx" Received: by smtp.kernel.org (Postfix) with ESMTPSA id 0E9D61F000E9; Mon, 10 Aug 2026 12:08:02 +0000 (UTC) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=linuxfoundation.org; s=korg; t=1786363683; bh=6HZ2Wpf+ISzAO8Wd/EwEPw8eOhrQCDSBysZrzDxBRz4=; h=From:To:Cc:Subject:Date:Reply-To; b=Xdlj+OnxqQMDAkqf0AFc1gg4Xm5X7wCa9jp36d5SntjH8oV0KX5cLLZNoRm6CBc1h zxc9I+jtcof+K0eZpHNZt7m4FQDPGEyrWor9QOjkCDG8mBRHlpcd6GcBTeK61QsNZV KwOvEMUEA6UOd3fv0lZMTVUTGngSFd8Ypy0zfbNk= From: Greg Kroah-Hartman To: linux-cve-announce@vger.kernel.org Cc: Greg Kroah-Hartman Subject: CVE-2026-68261: drm/imagination: fix error checking of pvr_vm_context_lookup() Date: Mon, 10 Aug 2026 13:59:38 +0200 Message-ID: <2026081022-CVE-2026-68261-14db@gregkh> X-Mailer: git-send-email 2.55.0 Reply-To: , Precedence: bulk X-Mailing-List: linux-cve-announce@vger.kernel.org List-Id: List-Subscribe: List-Unsubscribe: MIME-Version: 1.0 X-Developer-Signature: v=1; a=openpgp-sha256; l=5349; i=gregkh@linuxfoundation.org; h=from:subject:message-id; bh=HGprMFDrYQhU/KBlm9bDhgvyHe3Z4u0YdMl2ug/IpGk=; b=owGbwMvMwCRo6H6F97bub03G02pJDFmVexZ9Ufp+xSjg8cqVoU5Vtgo267al60atfKu344bsW wHuSdH1HbEsDIJMDLJiiixftvEc3V9xSNHL0PY0zBxWJpAhDFycAnCR9wzzLNev2yUZ5p3/U17l xLnNbEdYHi7/xbBghZ6iVH/LrocRR+/Lq2Z+W7lGJ6MKAA== X-Developer-Key: i=gregkh@linuxfoundation.org; a=openpgp; fpr=F4B60CC5BF78C2214A313DCB3147D40DDB2DFB29 Content-Transfer-Encoding: 8bit From: Greg Kroah-Hartman Description =========== In the Linux kernel, the following vulnerability has been resolved: drm/imagination: fix error checking of pvr_vm_context_lookup() Since pvr_vm_context_lookup() returns either NULL or a pointer, then stop using IS_ERR() for checking the return value. Using IS_ERR() leads to the kernel oops reported below. It can be reproduced by passing an invalid VM context handle from userspace to the DRM_IOCTL_PVR_CREATE_CONTEXT ioctl. [ 92.733119] Unable to handle kernel NULL pointer dereference at virtual address 0000000000000148 [ 92.742042] Mem abort info: [ 92.744890] ESR = 0x0000000096000004 [ 92.748686] EC = 0x25: DABT (current EL), IL = 32 bits [ 92.754020] SET = 0, FnV = 0 [ 92.757154] EA = 0, S1PTW = 0 [ 92.760337] FSC = 0x04: level 0 translation fault [ 92.765243] Data abort info: [ 92.768129] ISV = 0, ISS = 0x00000004, ISS2 = 0x00000000 [ 92.773626] CM = 0, WnR = 0, TnD = 0, TagAccess = 0 [ 92.778763] GCS = 0, Overlay = 0, DirtyBit = 0, Xs = 0 [ 92.784098] user pgtable: 4k pages, 48-bit VAs, pgdp=000000088ed23000 [ 92.790550] [0000000000000148] pgd=0000000000000000, p4d=0000000000000000 [ 92.797381] Internal error: Oops: 0000000096000004 [#1] SMP [ 92.803027] Modules linked in: powervr [ 92.852533] CPU: 0 UID: 0 PID: 409 Comm: triangle Not tainted 7.1.0-rc5-g98b46e693b91 #1 PREEMPT [ 92.861385] Hardware name: Texas Instruments AM68 SK (DT) [ 92.866766] pstate: 60000005 (nZCv daif -PAN -UAO -TCO -DIT -SSBS BTYPE=--) [ 92.873709] pc : pvr_vm_get_fw_mem_context+0x0/0xc [powervr] [ 92.879376] lr : pvr_queue_create+0x26c/0x440 [powervr] [ 92.884595] sp : ffff8000837fbb00 [ 92.887895] x29: ffff8000837fbb60 x28: 0000000000000000 x27: ffff8000837fbce8 [ 92.895015] x26: ffff000807f61a40 x25: ffff000807f61a00 x24: ffff000807f64400 [ 92.902135] x23: ffff00080a5ab000 x22: ffff800079b24730 x21: ffff000807f61800 [ 92.909254] x20: ffff00080999e680 x19: 0000000000000000 x18: 0000000000000000 [ 92.916373] x17: 0000000000000000 x16: 0000000000000000 x15: 0000000000000001 [ 92.923492] x14: 0000000000000000 x13: 0000000000000002 x12: ffff80008145b298 [ 92.930611] x11: ffff8000844e5000 x10: ffff80008165a130 x9 : 0000000000000100 [ 92.937730] x8 : 0000000000000001 x7 : ffff0008076b27e0 x6 : ffff00080ec43b7c [ 92.944850] x5 : ffff00080ec43b78 x4 : 0000000000000000 x3 : ffff00080999e680 [ 92.951968] x2 : 0000000000000000 x1 : 0000000000000000 x0 : 0000000000000000 [ 92.959088] Call trace: [ 92.961521] pvr_vm_get_fw_mem_context+0x0/0xc [powervr] (P) [ 92.967173] pvr_context_create+0x190/0x410 [powervr] [ 92.972218] pvr_ioctl_create_context+0x44/0x8c [powervr] [ 92.977608] drm_ioctl_kernel+0xbc/0x124 [drm] [ 92.982127] drm_ioctl+0x1f8/0x4dc [drm] [ 92.986098] __arm64_sys_ioctl+0xac/0x104 [ 92.990102] invoke_syscall+0x54/0x10c [ 92.993842] el0_svc_common.constprop.0+0x40/0xe0 [ 92.998532] do_el0_svc+0x1c/0x28 [ 93.001835] el0_svc+0x38/0x11c [ 93.004969] el0t_64_sync_handler+0xa0/0xe4 [ 93.009139] el0t_64_sync+0x198/0x19c [ 93.012792] Code: aa1703e0 d2800014 95cb0ba4 17ffffe8 (f940a400) [ 93.018869] ---[ end trace 0000000000000000 ]--- The Linux kernel CVE team has assigned CVE-2026-68261 to this issue. Affected and fixed versions =========================== Issue introduced in 6.8 with commit d2d79d29bb98a32c511f7339a8e93b47544fdeac and fixed in 6.12.101 with commit ce97192087c659f2e0c0c2a627330c7edcc9eeb3 Issue introduced in 6.8 with commit d2d79d29bb98a32c511f7339a8e93b47544fdeac and fixed in 6.18.42 with commit c45fafa69fe3f79e319369cf665da89868e3ef98 Issue introduced in 6.8 with commit d2d79d29bb98a32c511f7339a8e93b47544fdeac and fixed in 7.1.6 with commit 401fbe3b6bbb6c94c24ee8843b7beed5111491ac Issue introduced in 6.8 with commit d2d79d29bb98a32c511f7339a8e93b47544fdeac and fixed in 7.2-rc3 with commit cf385cf6e713eba0720651174dac0b2d2f5bb8f8 Please see https://www.kernel.org for a full list of currently supported kernel versions by the kernel community. Unaffected versions might change over time as fixes are backported to older supported kernel versions. The official CVE entry at https://cve.org/CVERecord/?id=CVE-2026-68261 will be updated if fixes are backported, please check that for the most up to date information about this issue. Affected files ============== The file(s) affected by this issue are: drivers/gpu/drm/imagination/pvr_context.c Mitigation ========== The Linux kernel CVE team recommends that you update to the latest stable kernel version for this, and many other bugfixes. Individual changes are never tested alone, but rather are part of a larger kernel release. Cherry-picking individual commits is not recommended or supported by the Linux kernel community at all. If however, updating to the latest release is impossible, the individual changes to resolve this issue can be found at these commits: https://git.kernel.org/stable/c/ce97192087c659f2e0c0c2a627330c7edcc9eeb3 https://git.kernel.org/stable/c/c45fafa69fe3f79e319369cf665da89868e3ef98 https://git.kernel.org/stable/c/401fbe3b6bbb6c94c24ee8843b7beed5111491ac https://git.kernel.org/stable/c/cf385cf6e713eba0720651174dac0b2d2f5bb8f8