Linuxカーネルにおいて、以下の脆弱性が修正されました:drm/virtio: virtio_gpu_dma_fence_wait() におけるエラー時の dma_fence 参照カウントリークの修正dma_fence_unwrap_for_each() は内部で dma_fence_unwrap_first() を呼び出し、この中で cursor->chain = dma_fence_get(head) により追加の参照を取得します。通常のループ完了時には、dma_fence_unwrap_next() が dma_fence_chain_walk() -> dma_fence_put() を通じてこの参照を解放します。しかし、virtio_gpu_do_fence_wait() が失敗し、ループ内から関数が早期リターンすると、cursor->chain の参照が解放されません。dma_fence_unwrap_for_each 内で早期リターンを行う呼び出し元は、カーネル全体でこれが唯一です。そのため、早期リターンの前に dma_fence_put(itr.chain) を追加します。
Linux Linux Kernel 6.13 以上 6.18.36 未満 Linux Kernel 6.19 以上 7.0.13 未満 Linux Kernel 6.5 以上 6.6.143 未満 Linux Kernel 6.7 以上 6.12.94 未満 Linux Kernel 7.1
・当該ソフトウェアが扱う情報について、外部への漏えいは発生しません。 ・当該ソフトウェアが扱う情報について、書き換えは発生しません。 ・当該ソフトウェアが完全に停止する可能性があります。
リリース情報、またはパッチ情報が公開されています。参考情報を参照して適切な対策を実施してください。
その他(CWE-Other) [NVD評価]
CVE-2026-53190
National Vulnerability Database (NVD) : CVE-2026-53190 関連文書 : drm/virtio: fix dma_fence refcount leak on error in virtio_gpu_dma_fence_wait() - kernel/git/stable/linux.git - Linux kernel stable tree (https://git.kernel.org/stable/c/73524e9f96a278b521f257a78a845c49eb522bc1) 関連文書 : drm/virtio: fix dma_fence refcount leak on error in virtio_gpu_dma_fence_wait() - kernel/git/stable/linux.git - Linux kernel stable tree (https://git.kernel.org/stable/c/c0fffc874c264292e769f26194a2a5e66ce31810) 関連文書 : drm/virtio: fix dma_fence refcount leak on error in virtio_gpu_dma_fence_wait() - kernel/git/stable/linux.git - Linux kernel stable tree (https://git.kernel.org/stable/c/8348567a6afb24e2c9cafe8a321162d0eebe1411) 関連文書 : drm/virtio: fix dma_fence refcount leak on error in virtio_gpu_dma_fence_wait() - kernel/git/stable/linux.git - Linux kernel stable tree (https://git.kernel.org/stable/c/898bd0ccfed71651b881660c5d20ad73b5203174) 関連文書 : drm/virtio: fix dma_fence refcount leak on error in virtio_gpu_dma_fence_wait() - kernel/git/stable/linux.git - Linux kernel stable tree (https://git.kernel.org/stable/c/3f26bb732cc136ab20176697c92f32c9c84cb125)
[2026年07月07日] 掲載