CVE-2026-31571: drm/i915: Unlink NV12 planes earlier
In the Linux kernel, the following vulnerability has been resolved:
drm/i915: Unlink NV12 planes earlier
unlinknv12plane() will clobber parts of the plane state potentially already set up by planeatomiccheck(), so we must make sure not to call the two in the wrong order. The problem happens when a plane previously selected as a Y plane is now configured as a normal plane by user space. planeatomiccheck() will first compute the proper plane state based on the userspace request, and unlinknv12plane() later clears some of the state.
This used to work on account of unlinknv12plane() skipping the state clearing based on the plane visibility. But I removed that check, thinking it was an impossible situation. Now when that situation happens unlinknv12plane() will just WARN and proceed to clobber the state.
Rather than reverting to the old way of doing things, I think it's more clear if we unlink the NV12 planes before we even compute the new plane state.
(cherry picked from commit 017ecd04985573eeeb0745fa2c23896fb22ee0cc)
Affected Software
Remediation
Event History
Frequently Asked Questions
What is the severity of CVE-2026-31571?
The severity of CVE-2026-31571 is classified as high due to the potential impact on system stability.
How do I fix CVE-2026-31571?
To fix CVE-2026-31571, you should update your Linux kernel to a version that is patched for this vulnerability.
What versions of the Linux kernel are affected by CVE-2026-31571?
CVE-2026-31571 affects Linux kernel versions from 6.15.1 to 6.18.21 and certain 7.0 release candidates.
What is the impact of CVE-2026-31571 on systems?
CVE-2026-31571 can lead to unstable system behavior due to improper handling of NV12 planes.
Is there a workaround for CVE-2026-31571?
Currently, there is no officially recommended workaround for CVE-2026-31571 other than applying the kernel update.