PT-2026-106642 · Linux · Linux

CVE-2026-98313

·

Publicado

2026-10-06

·

Atualizado

2026-10-06

Nenhuma

Não há classificações de severidade ou métricas disponíveis. Quando houver, atualizaremos as informações correspondentes na página.
In the Linux kernel, the following vulnerability has been resolved:
drm/msm/dp: skip PUSH IDLE when the link was never enabled
msm dp display atomic enable() returns early when link training fails, leaving ->power on false and the main link down. msm dp display atomic disable() nevertheless writes DP STATE CTRL PUSH IDLE and waits for an idle-pattern completion that cannot arrive, so every failed enable is followed by "PUSH IDLE pattern timedout".
Every other step of the teardown is already gated on that flag: msm dp display disable(), called from .atomic post disable(), returns early on !power on. The PUSH IDLE write is the only one that is not, so the controller's runtime-PM reference is then dropped without the link having been taken down.
On glymur (Snapdragon X2 Elite) the consequence is not a warning. The SoC does not survive it: TrustZone force-stops the SOCCP and ADSP remote processors and the machine resets silently about 50 ms later, with no oops and no panic. On an ASUS Zenbook A16 (UX3607OA), whose eDP panel does not currently train, this reproduces without any compositor or GPU involvement:

eDP enable has already failed with "Failed link training (rc=-104)"

echo 1 > /sys/class/graphics/fb0/blank
[535.645455] === marker === [535.694833] qcom q6v5 pas d00000.remoteproc: fatal error received: sys m smsm.c:512:TZ force stop [535.694875] remoteproc remoteproc0: crash detected in soccp: type fatal error [535.728857] qcom q6v5 pas 6800000.remoteproc: fatal error received: sys m smsm.c:783:err fatal notification received from TZ
Gate the PUSH IDLE write on ->power on so the disable path is consistent with the rest of the teardown. With this applied the same sequence is harmless and the machine stays up; without it, it resets every time.
The unconditional write dates back to the original DP driver (c943b4948b58 ("drm/msm/dp: add displayPort driver support")), but the surrounding code has been restructured several times since, so no Fixes: tag is offered.
Note that the eDP link-training failure that exposes this on the A16 is a separate problem in the glymur eDP PHY and is reported separately; this change is about not damaging the machine when training fails, for whatever reason.
Tested on ASUS Zenbook A16 (UX3607OA), Snapdragon X2 Elite Extreme, on linux-next next-20260803 and next-20260807. The machine has since been running next-20260807 with this patch as its daily driver.
Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Identificadores relacionados

CVE-2026-98313

Produtos afetados

Linux