« Volver al listado

CVE-2026-72327

Estado: RecibidaSin puntuar—

In the Linux kernel, the following vulnerability has been resolved:

drm/v3d: Reject invalid indirect BO handle in indirect CSD setup

v3d_get_cpu_indirect_csd_params() looks up the indirect buffer object from a userspace-supplied handle but never checks the result. A bogus or stale handle makes drm_gem_object_lookup() return NULL, which is then stored in info->indirect and only dereferenced later when the indirect CSD job runs, turning a userspace mistake into a NULL pointer dereference in the kernel.

Bail out with -ENOENT as soon as the lookup fails, so the bad handle is rejected at submission time.

CVSS

NVD no ha asignado puntuación CVSS a esta CVE (habitual desde el cambio de política de abril de 2026).

Probabilidad de explotación (EPSS)

EPSS (Exploit Prediction Scoring System, de FIRST) estima la probabilidad de que una vulnerabilidad sea explotada en 30 días. Complementa a CVSS (impacto) y a CISA KEV (explotación confirmada).

Tecnologías afectadas (1)

⚠ Inferidas por IA a partir de la descripción — NVD aún no ha analizado esta CVE; no son CPE verificados.

Referencias

JSON original (NVD)

Mostrar
{
  "id": "CVE-2026-72327",
  "cveTags": [],
  "metrics": {},
  "affected": [
    {
      "source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
      "affectedData": [
        {
          "repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
          "vendor": "Linux",
          "product": "Linux",
          "versions": [
            {
              "status": "affected",
              "version": "18b8413b25b7070fa2e55858a2c808e6909581d0",
              "lessThan": "7c27f630dc78b673e136cab7d410399a1c52146a",
              "versionType": "git"
            },
            {
              "status": "affected",
              "version": "18b8413b25b7070fa2e55858a2c808e6909581d0",
              "lessThan": "762116dfa72865c82151970960f7cf34f44b21c8",
              "versionType": "git"
            },
            {
              "status": "affected",
              "version": "18b8413b25b7070fa2e55858a2c808e6909581d0",
              "lessThan": "5d65dade4d84913d1879f3db6a12ac007e08314b",
              "versionType": "git"
            },
            {
              "status": "affected",
              "version": "18b8413b25b7070fa2e55858a2c808e6909581d0",
              "lessThan": "2f8b8593c7832fad655290cef9e99af05b1b52b3",
              "versionType": "git"
            }
          ],
          "programFiles": [
            "drivers/gpu/drm/v3d/v3d_submit.c"
          ],
          "defaultStatus": "unaffected"
        },
        {
          "repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
          "vendor": "Linux",
          "product": "Linux",
          "versions": [
            {
              "status": "affected",
              "version": "6.8"
            },
            {
              "status": "unaffected",
              "version": "0",
              "lessThan": "6.8",
              "versionType": "semver"
            },
            {
              "status": "unaffected",
              "version": "6.12.97",
              "versionType": "semver",
              "lessThanOrEqual": "6.12.*"
            },
            {
              "status": "unaffected",
              "version": "6.18.40",
              "versionType": "semver",
              "lessThanOrEqual": "6.18.*"
            },
            {
              "status": "unaffected",
              "version": "7.1.5",
              "versionType": "semver",
              "lessThanOrEqual": "7.1.*"
            },
            {
              "status": "unaffected",
              "version": "7.2",
              "versionType": "original_commit_for_fix",
              "lessThanOrEqual": "*"
            }
          ],
          "programFiles": [
            "drivers/gpu/drm/v3d/v3d_submit.c"
          ],
          "defaultStatus": "affected"
        }
      ]
    }
  ],
  "published": "2026-08-15T06:22:05.780",
  "references": [
    {
      "url": "https://git.kernel.org/stable/c/2f8b8593c7832fad655290cef9e99af05b1b52b3",
      "source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
    },
    {
      "url": "https://git.kernel.org/stable/c/5d65dade4d84913d1879f3db6a12ac007e08314b",
      "source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
    },
    {
      "url": "https://git.kernel.org/stable/c/762116dfa72865c82151970960f7cf34f44b21c8",
      "source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
    },
    {
      "url": "https://git.kernel.org/stable/c/7c27f630dc78b673e136cab7d410399a1c52146a",
      "source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
    }
  ],
  "vulnStatus": "Received",
  "descriptions": [
    {
      "lang": "en",
      "value": "In the Linux kernel, the following vulnerability has been resolved:\n\ndrm/v3d: Reject invalid indirect BO handle in indirect CSD setup\n\nv3d_get_cpu_indirect_csd_params() looks up the indirect buffer object\nfrom a userspace-supplied handle but never checks the result. A bogus\nor stale handle makes drm_gem_object_lookup() return NULL, which is\nthen stored in info->indirect and only dereferenced later when the\nindirect CSD job runs, turning a userspace mistake into a NULL pointer\ndereference in the kernel.\n\nBail out with -ENOENT as soon as the lookup fails, so the bad handle is\nrejected at submission time."
    }
  ],
  "lastModified": "2026-08-17T06:18:36.263",
  "sourceIdentifier": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
}