Improper Initialization in Linux kernel - CVE-2026-74453
Published: August 16, 2026
Vulnerability details
The vulnerability allows a local user to cause a denial of service.
The vulnerability exists due to improper initialization in the vc4 tile state data array handling when submitting crafted tile binning configurations. A local user can submit a crafted job that reuses stale tile state data to cause a denial of service.
The issue can result in invalid command streams, invalid primitive streams, and GPU hangs.
Affected software
Debian Linux
linux (Debian package)
How to mitigate CVE-2026-74453
linux (Debian package) - update to 6.12.105-1
External References
- https://git.kernel.org/stable/c/0e858422df2334165293ea742da9fbb2e51f2739
- https://git.kernel.org/stable/c/48a570c964d8e37d353381e4195106277e17f5cb
- https://git.kernel.org/stable/c/57667eb7548faaac396c6e39f3b4444dab5b097c
- https://git.kernel.org/stable/c/a75c8f365e209aa9bb927b0942a7840152d44892
- https://git.kernel.org/stable/c/f5802be65535f8818af7191159cf8c11f48ab2a2