Executive brief
A memory management issue was identified in the Linux kernel's V3D graphics driver, which is used to manage performance monitoring on certain hardware. The system fails to properly track and release memory references when configuring or deleting performance monitors. Over time, this could lead to memory exhaustion, potentially causing system instability or a denial-of-service condition.
Technical details
A reference counting vulnerability exists in drivers/gpu/drm/v3d/v3d_perfmon.c within the Linux kernel. The v3d_perfmon_find() function increments a reference count that is not properly decremented during several execution paths in v3d_perfmon_set_global_ioctl() and v3d_perfmon_delete(). Specifically, leaks occur during error paths in SET_GLOBAL, during CLEAR_GLOBAL operations, and when a performance monitor is destroyed while still active as the global monitor. This is a classic reference count leak that can lead to kernel memory exhaustion. Patches have been released for various stable branches including 6.18.36 and 7.0.13.
Affected products
- Linux Linux Kernel 6.14 to 7.1
Timeline
- 2026-05-31: other: Initial patch authored
- 2026-06-25: advisory: NVD publication date