Junglewise Threat Intelligence

CVE-2026-64099: Linux Kernel drm/v3d use-after-free in CPU job error path

CVE-2026-64099 · Severity: info · CVSS 0 · Published 2026-07-19

Technologies: Linux Kernel. Vendors: Linux.

Executive brief

A vulnerability was identified in the Linux kernel's V3D graphics driver, which is used to manage GPU operations. A flaw in how the system handles errors during graphics tasks could lead to a system crash or unpredictable behavior. This issue primarily affects the stability and reliability of systems using specific Broadcom V3D graphics hardware.

Technical details

A use-after-free vulnerability exists in the Broadcom V3D (Direct Rendering Manager) driver within the Linux kernel. The flaw is located in the error handling path of the CPU job ioctl, where the 'fail' label calls kvfree() on query arrays after the job's reference count has already reached zero and been freed by v3d_job_cleanup(). Additionally, an early failure in v3d_job_init() can trigger a NULL pointer dereference because the local pointer is zeroed before being accessed. The error path also failed to properly release syncobj references, leading to resource leaks. The fix unifies the teardown process into the kref destructor to ensure resources are freed exactly once regardless of whether the job succeeded or failed.

Affected products

  • Linux Linux Kernel 6.8 to 6.12.93

Timeline

  • 2026-05-15: disclosed: Initial patch authored
  • 2026-06-01: patched: Patch committed to stable tree
  • 2026-07-19: advisory: CVE published

References

Related threats