CVE-2026-68437: drm/imagination: Fit paired fragment job in the correct CCCB

Published Aug 12, 2026
·
Updated

In the Linux kernel, the following vulnerability has been resolved:

drm/imagination: Fit paired fragment job in the correct CCCB

For geometry jobs with a paired fragment job, at the moment, the DRM scheduler's preparejob() callback:

- checks for internal (driver) dependencies for the geometry job; - calls into pvrqueuegetpairedfragjobdep() to check for external dependencies for the fragment job (the two jobs are submitted together but the common scheduler code doesn't know about it, so this needs to be done at this point in time); - calls into the preparejob() callback again, but for the fragment job, to check its internal dependencies as well, passing the fragment job's drmschedjob and the geometry job's drmschedentity / pvrqueue.

The problem with the last step is that pvrqueuepreparejob() doesn't always take the mismatched fragment job and geometry queue into account, in particular when checking whether there is space for the fragment command to be submitted, so the code ends up checking for space in the geometry (i.e. wrong) CCCB. The rest of the nested preparejob() callback happens to work fine at the moment as the other internal dependencies are not relevant for a paired fragment job.

Move the initialisation of a paired fragment job's done fence and CCCB fence to pvrqueuegetpairedfragjobdep(), inferring the correct queue from the fragment job itself.

This fixes cases where preparejob() wrongly assumed that there was enough space for a paired fragment job in its own CCCB, unblocking runjob(), which then returned early without writing the full sequence of commands to the CCCB.

The above lead to kernel warnings such as the following and potentially job timeouts (depending on waiters on the missing commands):

[ 552.421075] WARNING: drivers/gpu/drm/imagination/pvrcccb.c:178 at pvrcccbwritecommandwithheader+0x2c4/0x330 [powervr], CPU#2: kworker/u16:5/63 [ 552.421230] Modules linked in: [ 552.421592] CPU: 2 UID: 0 PID: 63 Comm: kworker/u16:5 Tainted: G W 7.0.0-rc2-gc5d053e4dccb #39 PREEMPT [ 552.421625] Tainted: [W]=WARN [ 552.421637] Hardware name: Texas Instruments AM625 SK (DT) [ 552.421655] Workqueue: powervr-sched drmschedrunjobwork [gpusched] [ 552.421744] pstate: 80000005 (Nzcv daif -PAN -UAO -TCO -DIT -SSBS BTYPE=--) [ 552.421766] pc : pvrcccbwritecommandwithheader+0x2c4/0x330 [powervr] [ 552.421850] lr : pvrqueuesubmitjobtocccb+0x57c/0xa74 [powervr] [ 552.421923] sp : ffff800084c47650 [ 552.421936] x29: ffff800084c47740 x28: 0000000000000df8 x27: ffff800088a77000 [ 552.421979] x26: 0000000000000030 x25: ffff800084c47680 x24: 0000000000001000 [ 552.422017] x23: ffff800084c47820 x22: 1ffff00010988ecc x21: 0000000000000008 [ 552.422055] x20: 0000000000000208 x19: ffff000006ad5a88 x18: 0000000000000000 [ 552.422093] x17: 0000000020020000 x16: 0000000000020000 x15: 0000000000000000 [ 552.422130] x14: 0000000000000000 x13: 0000000000000000 x12: 0000000000000000 [ 552.422167] x11: 000000000000f2f2 x10: 00000000f3000000 x9 : 00000000f3f3f3f3 [ 552.422204] x8 : 00000000f2f2f200 x7 : ffff700010988ecc x6 : 0000000000000008 [ 552.422241] x5 : 0000000000000000 x4 : 1ffff0001114ee00 x3 : 0000000000000000 [ 552.422278] x2 : 0000000000000007 x1 : 0000000000000fff x0 : 000000000000002f [ 552.422316] Call trace: [ 552.422330] pvrcccbwritecommandwithheader+0x2c4/0x330 [powervr] (P) [ 552.422411] pvrqueuesubmitjobtocccb+0x57c/0xa74 [powervr] [ 552.422486] pvrqueuerunjob+0x3a4/0x990 [powervr] [ 552.422562] drmschedrunjobwork+0x580/0xd48 [gpusched] [ 552.422623] processonework+0x520/0x1288 [ 552.422657] workerthread+0x3f0/0xb3c [ 552.422679] kthread+0x334/0x3d8 [ 552.422706] retfromfork+0x10/0x20

Affected Software

1 affected component
Linux kernel drm/imagination (powervr / PVR CCCB scheduler)

Event History

Aug 12, 2026
CVE Published
via MITRE·12:07 AM
Data Sourced
via MITRE·12:07 AM
Description
Data Sourced
via NVD·12:17 AM
Description
Free Weekly Intel

Don't miss critical vulnerabilities

Join thousands of security professionals who receive our weekly digest of trending CVEs, zero-days, and exploited vulnerabilities.

No spam. Unsubscribe anytime.

Frequently Asked Questions

1

What is the severity of CVE-2026-68437?

CVE-2026-68437 has a risk level of 17.

2

How do I fix CVE-2026-68437?

To mitigate CVE-2026-68437, ensure you update the Linux kernel to a version that includes the security fix.

3

What type of vulnerability is CVE-2026-68437?

CVE-2026-68437 is related to the Direct Rendering Manager (DRM) in the Linux kernel.

4

Who is affected by CVE-2026-68437?

Users of the Linux kernel who utilize the DRM for graphics rendering may be affected by CVE-2026-68437.

5

Is CVE-2026-68437 exploitable?

Yes, CVE-2026-68437 may be exploitable in scenarios involving geometry jobs with paired fragment jobs.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203