CVE-2026-53190 Details
Description
In the Linux kernel, the following vulnerability has been resolved: drm/virtio: fix dma_fence refcount leak on error in virtio_gpu_dma_fence_wait() dma_fence_unwrap_for_each() internally calls dma_fence_unwrap_first() which does cursor->chain = dma_fence_get(head), taking an extra reference. On normal loop completion, dma_fence_unwrap_next() releases this via dma_fence_chain_walk() -> dma_fence_put(). When virtio_gpu_do_fence_wait() fails and the function returns early from inside the loop, the cursor->chain reference is never released. This is the only caller in the entire kernel that does an early return inside dma_fence_unwrap_for_each. Add dma_fence_put(itr.chain) before the early return.
A reference count leak vulnerability has been identified in the Linux kernel's Virtio GPU driver. This issue arises in the 'virtio_gpu_dma_fence_wait()' function, where an early return can occur without releasing a previously acquired reference. The problem is triggered during the processing of DMA fences, specifically when the 'virtio_gpu_do_fence_wait()' function encounters an error and exits prematurely. As a result, the reference count for the DMA fence is not properly decremented, leading to a potential memory management issue.
Users can apply the latest patches available in the Linux kernel stable tree to address this vulnerability. The patch can be downloaded from the Linux kernel Git repository.
Metrics
CVSS 4.0 Severity and Vector Strings:
No CVSS 4.0 data is available for this CVE.
CVSS 3.x Severity and Vector Strings:
No data available for CVSS Version 2.0 on this CVE.
No SSVC data is available for this CVE.
References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.
| URL | Source(s) | Tag(s) |
|---|---|---|
| https://git.kernel.org/stable/c/3f26bb732cc136ab20176697c92f32c9c84cb125 | kernel.org | Patch |
| https://git.kernel.org/stable/c/73524e9f96a278b521f257a78a845c49eb522bc1 | kernel.org | Patch |
| https://git.kernel.org/stable/c/8348567a6afb24e2c9cafe8a321162d0eebe1411 | kernel.org | Patch |
| https://git.kernel.org/stable/c/898bd0ccfed71651b881660c5d20ad73b5203174 | kernel.org | Patch |
| https://git.kernel.org/stable/c/c0fffc874c264292e769f26194a2a5e66ce31810 | kernel.org | Patch |
Weakness Enumeration
| CWE-ID | CWE Name | Source |
|---|---|---|
| NVD-CWE-Other | Weakness Not in a Standard CWE Category | [email protected] |
Affected Products
| Product | Versions |
|---|---|
| linux linux kernel | >= 6.5, < 6.6.143 >= 6.7, < 6.12.94 >= 6.13, < 6.18.36 >= 6.19, < 7.0.13 7.1 rc1 7.1 rc2 7.1 rc3 7.1 rc4 7.1 rc5 7.1 rc6 7.1 rc7 |
CPE
Remediation
| |
Change History
2 change records found show changes
| Date | Action | Recorded By |
|---|---|---|
| Jul 6, 2026 | Initial Analysis | [email protected] |
| Jun 25, 2026 | New CVE Received | kernel.org |