CVE.RADIO
FREN

CVE-2026-53285

LinuxVulnerabilityCVSS 5.5Patched

In the Linux kernel, the following vulnerability has been resolved: drm/amd/display: Wrap DCN32 phantom-plane allocation in DC_RUN_WITH_PREEMPTION_ENABLED [Why] dcn32_validate_bandwidth() wraps dcn32_internal_validate_bw() with DC_FP_START()/DC_FP_END(). In x86 non-RT, DC_FP_START takes fpregs_lock(), which disables local softirqs. The DML1 path through dcn32_enable_phantom_plane() calls kvzalloc() to allocate ~335 KiB for dc_plane_state. This triggers the vmalloc path, which calls BUG_ON(in_interrupt()) because it's invoked within the FPU-enabled (softirq disabled) region, leading to a kernel crash. [How] Wrap the dc_state_create_phantom_plane() call with the DC_RUN_WITH_PREEMPTION_ENABLED() macro to allow preemption during this memory allocation. (cherry picked from commit 885ccbef7b94a8b38f69c4211c679021aa27ad11)

No public exploitation has been reported so far. A fixed version is available (see the table below).

Recommended action: Update to the fixed version listed for your distribution using the native package manager.

CVE-2026-53285 Linux Vulnerability

Severity metrics

CVSS 3.1 : 5.5 MEDIUM

Attack vectorLocal
Attack complexityLow
Privileges requiredLow
User interactionNone
ScopeUnchanged
Confidentiality impactNone
Integrity impactNone
Availability impactHigh

Vector: AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H

Affected & fixed versions by distribution

Versions are the native distribution strings (backport-aware): RHEL/Debian/SUSE backport fixes, so compare with the distro version comparator (dpkg / rpm / vercmp), not the upstream version.

DistributionPackageAffectedFixed versionStatus
SUSE:Linux Micro 6.2kernel-default-base-6.12.0-160000.36.1.160000.2.17fixed
openSUSE:Leap 16.0kernel-default-6.12.0-160000.36.1fixed
openSUSE:Leap 16.0kernel-default-base-6.12.0-160000.36.1.160000.2.17fixed

Sources

Published 2026-06-26 · updated 2026-07-25 · source: NVD