Junglewise Threat Intelligence

CVE-2026-53056: Linux Kernel MSM DRM instability in DPU power management

CVE-2026-53056 · Severity: info · CVSS 5.5 · Published 2026-06-24

Technologies: Linux. Vendors: Linux.

Executive brief

A vulnerability in the Linux kernel's display driver for Qualcomm chipsets can cause system instability or crashes. This occurs due to a technical mismatch between power delivery and processor speed during certain power-saving transitions. An exploit could lead to a denial of service, impacting system availability and operational uptime.

Technical details

A race condition and logic error exist in the drm/msm/dpu driver during runtime suspend/resume cycles. Specifically, calling dev_pm_opp_set_rate(dev, 0) during suspend drops the MMCX rail voltage to a minimum level (MIN_SVS) while the core clock frequency remains at its maximum rate. Upon resume, the clock is re-enabled at high frequency before the voltage is appropriately scaled back up, leading to a state where the rail cannot sustain the clock rate. This results in hardware instability or a kernel panic (system crash). The fix involves removing the premature rate reset in dpu_runtime_suspend to ensure voltage and frequency remain synchronized.

Affected products

  • Linux Linux versions before 6.1.92, 6.6.32, 6.8.11, 6.9.2 (based on stable branch patterns)

Timeline

  • 2026-03-09: other: Patch submitted to mailing list
  • 2026-05-23: patched: Commits merged into stable branches
  • 2026-06-24: disclosed: CVE published

References