---
cve: "CVE-2026-53285"
severity: "LOW"
cvss: 3.1
epss: "11%"
vendor: "Linux"
kev: false
exploited: false
published: "2026-06-26 20:17:21"
tags: [cve, security, low]
source: tsecurity.de CVE-Dossier
exported: "2026-09-08T04:16:44+02:00"
---

# CVE-2026-53285

> 3.1 LOW

## Beschreibung

In the Linux kernel, the following vulnerability has been resolved:

drm/amd/display: Wrap DCN32 phantom-plane allocation in DC_RUN_WITH_PREEMPTION_ENABLED

[Why]
dcn32_validate_bandwidth() wraps dcn32_internal_validate_bw() with
DC_FP_START()/DC_FP_END(). In x86 non-RT, DC_FP_START takes fpregs_lock(),
which disables local softirqs.

The DML1 path through dcn32_enable_phantom_plane() calls kvzalloc() to
allocate ~335 KiB for dc_plane_state. This triggers the vmalloc path,
which calls BUG_ON(in_interrupt()) because it's invoked within the
FPU-enabled (softirq disabled) region, leading to a kernel crash.

[How]
Wrap the dc_state_create_phantom_plane() call with the
DC_RUN_WITH_PREEMPTION_ENABLED() macro to allow preemption during
this memory allocation.

(cherry picked from commit 885ccbef7b94a8b38f69c4211c679021aa27ad11)

## Patch verfügbar (OSV)

- Kernel ≥ 7.0.10

## Referenzen

- <https://git.kernel.org/stable/c/30bb2ec6695d62f63db4aa6179c4626834ed0cd6>
- <https://git.kernel.org/stable/c/183182235f6d53bac62c6c39014738a54a68dfa6>

---
_Exportiert aus dem [tsecurity.de CVE-Dossier](https://tsecurity.de/cve?cve=CVE-2026-53285) · Datenquellen: EUVD (ENISA), NVD, OSV, CISA KEV, FIRST EPSS, Exploit-DB, BSI BITS_
