Executive brief
A vulnerability in the Linux kernel's display driver for Qualcomm chipsets can cause system instability or crashes. This occurs due to a technical mismatch between power delivery and processor speed during certain power-saving transitions. An exploit could lead to a denial of service, impacting system availability and operational uptime.
Technical details
A race condition and logic error exist in the drm/msm/dpu driver during runtime suspend/resume cycles. Specifically, calling dev_pm_opp_set_rate(dev, 0) during suspend drops the MMCX rail voltage to a minimum level (MIN_SVS) while the core clock frequency remains at its maximum rate. Upon resume, the clock is re-enabled at high frequency before the voltage is appropriately scaled back up, leading to a state where the rail cannot sustain the clock rate. This results in hardware instability or a kernel panic (system crash). The fix involves removing the premature rate reset in dpu_runtime_suspend to ensure voltage and frequency remain synchronized.
Affected products
- Linux Linux versions before 6.1.92, 6.6.32, 6.8.11, 6.9.2 (based on stable branch patterns)
Timeline
- 2026-03-09: other: Patch submitted to mailing list
- 2026-05-23: patched: Commits merged into stable branches
- 2026-06-24: disclosed: CVE published
References
- https://git.kernel.org/stable/c/0ccf4f27b4652570b5de3de02a89a86435559de9
- https://git.kernel.org/stable/c/0f7dd5839cfabaf9c007fb718ec66e907a473c93
- https://git.kernel.org/stable/c/1181a7028d37e0b1e720a36125a03f5db97e3d27
- https://git.kernel.org/stable/c/9830999c9e065c1813ec5435bfe4eab98ee54a87
- https://git.kernel.org/stable/c/bc1dccc518cc5ab5140fba06c27e7188e0ed342b
- https://git.kernel.org/stable/c/c5735c7d0eef7a5240f9c1c66e44ba52a1be58d6