Linux kernel drm_exec: empty object array leaves contention unresolved and spins forever
Impact
drm_exec_prepare_array() returned success without calling drm_exec_lock_contended() when handed an empty array, breaking the invariant that every entry into the locking sequence first retries the previously contended buffer object. Drivers that chain two prepare_array() calls per locking iteration - amdgpu's user-queue signal and wait ioctls, which prepare separate read and write BO arrays - can pass one empty array, so on contention the retry loop never reaches the call that would clear it and spins indefinitely. The practical effect on an AMD GPU node is a kernel thread burning a core in an unbreakable loop, triggered by an ordinary ioctl from a tenant workload. No CVSS score or CWE is attached.
Who can reach it
Local user with access to an AMD GPU render node (any tenant with a GPU pod holding /dev/dri/render*) submitting user-queue signal/wait ioctls with one empty BO array under lock contention. No authentication beyond device access; not remotely reachable.
What to do
Update to a stable kernel where drm_exec_prepare_array() calls drm_exec_lock_contended() directly for the zero-object case, and reboot the affected AMD GPU nodes. The record lists stable commits only, with no fixed release numbers. A node already stuck in the loop will need a reboot regardless.
References
Related entries
- Linux kernel accel/qaic: unbounded response message walk in resp_worker() reads past the slab allocationCVE-2026-98155 · Linux kernel accel/qaic (Qualcomm Cloud AI 100 accelerator driver)Unscored
- GPU / accelerator firmware (VBIOS, GSP, NVSwitch): GPU-resident firmware sits below the host OS and is not coveredNCVD-0000-012-gpu-accelerator-firmware-vbios-g · GPU / accelerator firmware (VBIOS, GSP, NVSwitch)Unscored
- NVIDIA Multi-Instance GPU (MIG) partitioning: MIG gives each instance its own SM slice, L2 slice, memory slice andNCVD-2020-001-nvidia-multi-instance-gpu-mig-pa · NVIDIA Multi-Instance GPU (MIG) partitioningUnscored
- NVIDIA Multi-Instance GPU (MIG) partitioning: MIG gives each instance its own SM slice, L2 slice, memory slice andNCVD-2020-003-nvidia-multi-instance-gpu-mig-pa · NVIDIA Multi-Instance GPU (MIG) partitioningUnscored
- Integrated GPU graphics data compression (Intel, AMD, Apple, Arm, Qualcomm, NVIDIA): GPUs apply data-dependent losslessNCVD-2023-003-integrated-gpu-graphics-data-com · Integrated GPU graphics data compression (Intel, AMD, Apple, Arm, Qualcomm, NVIDIA)Unscored
- NVIDIA Confidential Computing (H100/H200/B100/B200/GB200) - CC-DevTools operating mode: NVIDIA GPU confidentialNCVD-2023-004-nvidia-confidential-computing-h1 · NVIDIA Confidential Computing (H100/H200/B100/B200/GB200) - CC-DevTools operating modeUnscored
This entry is curated: imported from vendor advisories with machine assistance, not yet individually verified. Confirm against your vendor's advisory before acting, and report anything wrong.