Unrated severityNVD Advisory· Published Aug 10, 2026
CVE-2026-68233
CVE-2026-68233
Description
In the Linux kernel, the following vulnerability has been resolved:
drm/vc4: Shut down BO cache timer before teardown
The BO cache timer callback schedules time_work, and time_work can rearm the timer through vc4_bo_cache_free_old().
vc4_bo_cache_destroy() deletes the timer and then cancels the work, which does not break that cycle: the work being cancelled can rearm the timer, and the timer then queues work again after teardown.
Use timer_shutdown_sync() instead, so the timer cannot be rearmed and the cycle ends with cancel_work_sync().
Affected products
1Patches
Vulnerability mechanics
References
3News mentions
0No linked articles in our index yet.