CVE-2026-98313
Received Received - Intake

Kernel panic due to unhandled DP PUSH_IDLE in msm driver

Vulnerability report for CVE-2026-98313, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-10-06

Last updated on: 2026-10-06

Assigner: kernel.org

Description

In the Linux kernel, the following vulnerability has been resolved: drm/msm/dp: skip PUSH_IDLE when the link was never enabled msm_dp_display_atomic_enable() returns early when link training fails, leaving ->power_on false and the main link down. msm_dp_display_atomic_disable() nevertheless writes DP_STATE_CTRL_PUSH_IDLE and waits for an idle-pattern completion that cannot arrive, so every failed enable is followed by "PUSH_IDLE pattern timedout". Every other step of the teardown is already gated on that flag: msm_dp_display_disable(), called from .atomic_post_disable(), returns early on !power_on. The PUSH_IDLE write is the only one that is not, so the controller's runtime-PM reference is then dropped without the link having been taken down. On glymur (Snapdragon X2 Elite) the consequence is not a warning. The SoC does not survive it: TrustZone force-stops the SOCCP and ADSP remote processors and the machine resets silently about 50 ms later, with no oops and no panic. On an ASUS Zenbook A16 (UX3607OA), whose eDP panel does not currently train, this reproduces without any compositor or GPU involvement: # eDP enable has already failed with "Failed link training (rc=-104)" echo 1 > /sys/class/graphics/fb0/blank [535.645455] === marker === [535.694833] qcom_q6v5_pas d00000.remoteproc: fatal error received: \ sys_m_smsm.c:512:TZ force stop [535.694875] remoteproc remoteproc0: crash detected in soccp: type fatal error [535.728857] qcom_q6v5_pas 6800000.remoteproc: fatal error received: \ sys_m_smsm.c:783:err fatal notification received from TZ <SoC reset> Gate the PUSH_IDLE write on ->power_on so the disable path is consistent with the rest of the teardown. With this applied the same sequence is harmless and the machine stays up; without it, it resets every time. The unconditional write dates back to the original DP driver (c943b4948b58 ("drm/msm/dp: add displayPort driver support")), but the surrounding code has been restructured several times since, so no Fixes: tag is offered. Note that the eDP link-training failure that exposes this on the A16 is a separate problem in the glymur eDP PHY and is reported separately; this change is about not damaging the machine when training fails, for whatever reason. Tested on ASUS Zenbook A16 (UX3607OA), Snapdragon X2 Elite Extreme, on linux-next next-20260803 and next-20260807. The machine has since been running next-20260807 with this patch as its daily driver. Patchwork: https://patchwork.freedesktop.org/patch/745167/

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-10-06
Last Modified
2026-10-06
Generated
2026-10-06
AI Q&A
2026-10-06
EPSS Evaluated
N/A
NVD
EUVD

Affected Vendors & Products

Showing 5 associated CPEs
Vendor Product Version / Range
Linux Linux 1da177e4c3f41524e886b7f1b8a0c1fc7321cac2
Linux Linux 1da177e4c3f41524e886b7f1b8a0c1fc7321cac2
Linux Linux 1da177e4c3f41524e886b7f1b8a0c1fc7321cac2
Linux Linux 0
Linux Linux 0

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-UNKNOWN

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

This vulnerability is in the Linux kernel's DisplayPort (DP) driver for Qualcomm's msm (Snapdragon) hardware. When link training fails during display enablement, the driver incorrectly writes a PUSH_IDLE command during teardown even though the link was never properly enabled. This causes the system to hang waiting for an idle pattern that never arrives, leading to a silent reset on some Qualcomm systems like the Snapdragon X2 Elite.

Detection Guidance

This vulnerability is specific to the Linux kernel's msm_dp driver and manifests as a silent system reset when eDP link training fails. Detection requires checking kernel logs for 'PUSH_IDLE pattern timedout' or 'TZ force stop' errors after eDP operations. Monitor logs with: dmesg | grep -i 'PUSH_IDLE\|TZ force stop\|remoteproc'.

Impact Analysis

On affected systems, this vulnerability can cause sudden silent reboots without warning or crash logs when display operations fail. Users may experience unexpected system resets during normal operations, particularly when connecting or enabling displays. The issue is most severe on Qualcomm-based systems like the Snapdragon X2 Elite where it triggers a TrustZone force-stop of critical processors.

Mitigation Strategies

Apply the kernel patch from https://patchwork.freedesktop.org/patch/745167/ which gates the PUSH_IDLE write on ->power_on. Alternatively, avoid triggering eDP link training failures by ensuring proper display configuration. If using affected hardware, update to a patched kernel version.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-98313. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart