PT-2026-72906 · Linux · Linux Kernel
CVE-2026-74454
·
Published
2026-08-15
·
Updated
2026-08-18
CVSS v3.1
7.8
High
| Vector | AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
Linux kernel (affected versions not specified)
Description
An issue exists in the
drm/vc4 component where the vc4 overflow mem work() function incorrectly writes the size of the entire binner Buffer Object (BO) to the BPOS variable instead of the specific 512KB overflow slot size. During binner out-of-memory events, this allows the Page Table Builder (PTB) to write tile lists across other slots and into unrelated Contiguous Memory Allocator (CMA) memory. Because CMA pages are recycled for user allocations and page cache, this leads to arbitrary memory corruption via GPU Direct Memory Access (DMA). This may result in GPU hangs, userspace heap corruption, or full system crashes when a job overflows the initial binner slot.Recommendations
At the moment, there is no information about a newer version that contains a fix for this vulnerability.
Exploit
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Linux Kernel