What is CVE-2026-74453?
A vulnerability in the Linux kernel's 'drm/vc4' driver fails to zero the tile state data array before each BIN job, leading to potential information leakage from the recycled 512KB slots in the binner buffer. This could expose stale graphics data across jobs. Updating the kernel is recommended to resolve the issue.
Azərbaycanca: Linux nüvəsindəki 'drm/vc4' sürücüsündə BIN işi üçün tile_state məlumat massivinin sıfırlanmaması səbəbindən köhnə məlumatın sızması zəifliyi aşkarlanıb. Bu, təkrarlanan 512KB slotlarda saxlanılan həssas qrafik məlumatlarının digər işlərə ifşa olmasına yol aça bilər. Problemi aradan qaldırmaq üçün kernel yeniləməsi tətbiq edilməlidir.
Related CVEs
link basis: same weakness class CWE-200
FAQ2
In which kernel driver was CVE-2026-74453 discovered?
The vulnerability was discovered in the 'drm/vc4' driver of the Linux kernel.
What could happen as a result of this vulnerability?
Because the tile state array is not zeroed before each BIN job, stale graphics data stored in the recycled 512KB slots could be exposed to other jobs.
See also6
This explainer is AI-written from source data — skopnix's own reporting on this CVE; CVSS scores, vendors and versions are never invented. See NVD for the official record.