CVE-2025-68184: drm/mediatek: Disable AFBC support on Mediatek DRM driver

Published Dec 16, 2025
·
Updated

In the Linux kernel, the following vulnerability has been resolved:

drm/mediatek: Disable AFBC support on Mediatek DRM driver

Commit c410fa9b07c3 ("drm/mediatek: Add AFBC support to Mediatek DRM driver") added AFBC support to Mediatek DRM and enabled the 32x8/split/sparse modifier.

However, this is currently broken on Mediatek MT8188 (Genio 700 EVK platform); tested using upstream Kernel and Mesa (v25.2.1), AFBC is used by default since Mesa v25.0.

Kernel trace reports vblank timeouts constantly, and the render is garbled:

[CRTC:62:crtc-0] vblank wait timed out WARNING: CPU: 7 PID: 70 at drivers/gpu/drm/drmatomichelper.c:1835 drmatomichelperwaitforvblanks.part.0+0x24c/0x27c [...] Hardware name: MediaTek Genio-700 EVK (DT) Workqueue: eventsunbound commitwork pstate: 60400009 (nZCv daif +PAN -UAO -TCO -DIT -SSBS BTYPE=--) pc : drmatomichelperwaitforvblanks.part.0+0x24c/0x27c lr : drmatomichelperwaitforvblanks.part.0+0x24c/0x27c sp : ffff80008337bca0 x29: ffff80008337bcd0 x28: 0000000000000061 x27: 0000000000000000 x26: 0000000000000001 x25: 0000000000000000 x24: ffff0000c9dcc000 x23: 0000000000000001 x22: 0000000000000000 x21: ffff0000c66f2f80 x20: ffff0000c0d7d880 x19: 0000000000000000 x18: 000000000000000a x17: 000000040044ffff x16: 005000f2b5503510 x15: 0000000000000000 x14: 0000000000000000 x13: 74756f2064656d69 x12: 742074696177206b x11: 0000000000000058 x10: 0000000000000018 x9 : ffff800082396a70 x8 : 0000000000057fa8 x7 : 0000000000000cce x6 : ffff8000823eea70 x5 : ffff0001fef5f408 x4 : ffff80017ccee000 x3 : ffff0000c12cb480 x2 : 0000000000000000 x1 : 0000000000000000 x0 : ffff0000c12cb480 Call trace: drmatomichelperwaitforvblanks.part.0+0x24c/0x27c (P) drmatomichelpercommittailrpm+0x64/0x80 committail+0xa4/0x1a4 commitwork+0x14/0x20 processonework+0x150/0x290 workerthread+0x2d0/0x3ec kthread+0x12c/0x210 retfromfork+0x10/0x20 ---[ end trace 0000000000000000 ]---

Until this gets fixed upstream, disable AFBC support on this platform, as it's currently broken with upstream Mesa.

Affected Software

1 affected component
Linux Foundation Linux kernel (drm/mediatek)

Remediation

Recommended actions to resolve this vulnerability, in priority order.

  1. Configuration

    On the affected Mediatek MT8188 (MediaTek Genio-700 EVK) platform, disable AFBC support in the Mediatek DRM driver because AFBC is currently broken upstream (kernel trace shows vblank timeouts and garbled render).

    Linux kernel DRM Mediatek driver AFBC support = disabled

Event History

Dec 16, 2025
CVE Published
via MITRE·01:43 PM
Data Sourced
via MITRE·01:43 PM
DescriptionSeverity
Data Sourced
via NVD·02:15 PM
DescriptionSeverity
Free Weekly Intel

Don't miss critical vulnerabilities

Join thousands of security professionals who receive our weekly digest of trending CVEs, zero-days, and exploited vulnerabilities.

No spam. Unsubscribe anytime.

Frequently Asked Questions

1

What is the severity of CVE-2025-68184?

CVE-2025-68184 has been classified as a high severity vulnerability affecting the Linux kernel.

2

How do I fix CVE-2025-68184?

To mitigate CVE-2025-68184, update the Linux kernel to version 25.0 or later.

3

What systems are affected by CVE-2025-68184?

CVE-2025-68184 affects systems running the Linux kernel up to version 25.0 that utilize the Mediatek DRM driver.

4

What does CVE-2025-68184 affect in the Linux kernel?

CVE-2025-68184 specifically affects the AFBC support implementation in the Mediatek DRM driver.

5

Is there a specific patch for CVE-2025-68184?

Yes, a specific patch has been incorporated into the latest kernel to address CVE-2025-68184.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203