AUGUST 15, 2026
Live Feed
Back to database
Case File

CVE-2026-72327

UNKNOWN · CVSS N/A

Source: NVD + CISA KEV + EPSS · Published 2026-08-15 · Last synced 2026-08-15

CyberRota Analysis

AI-Generated

The vulnerability affects the Linux kernel's handling of indirect buffer object (BO) handles in the v3d driver, where a failure to validate user-supplied handles can lead to a NULL pointer dereference during indirect command submission. This flaw can allow attackers to trigger kernel crashes or potentially execute arbitrary code, impacting system stability and security. Organizations utilizing Linux systems with graphics processing capabilities should prioritize addressing this vulnerability to mitigate risks associated with user input handling in the kernel.

CVE
CVE-2026-72327
Severity
UNKNOWN
CVSS
N/A
EPSS
N/A
Linux

Original NVD Description

In the Linux kernel, the following vulnerability has been resolved: drm/v3d: Reject invalid indirect BO handle in indirect CSD setup v3d_get_cpu_indirect_csd_params() looks up the indirect buffer object from a userspace-supplied handle but never checks the result. A bogus or stale handle makes drm_gem_object_lookup() return NULL, which is then stored in info->indirect and only dereferenced later when the indirect CSD job runs, turning a userspace mistake into a NULL pointer dereference in the kernel. Bail out with -ENOENT as soon as the lookup fails, so the bad handle is rejected at submission time.