CVE-2026-53056
drm/msm/dpu: fix mismatch between power and frequency
Description
In the Linux kernel, the following vulnerability has been resolved: drm/msm/dpu: fix mismatch between power and frequency During DPU runtime suspend, calling dev_pm_opp_set_rate(dev, 0) drops the MMCX rail to MIN_SVS while the core clock frequency remains at its original (highest) rate. When runtime resume re-enables the clock, this may result in a mismatch between the rail voltage and the clock rate. For example, in the DPU bind path, the sequence could be: cpu0: dev_sync_state -> rpmhpd_sync_state cpu1: dpu_kms_hw_init timeline 0 ------------------------------------------------> t After rpmhpd_sync_state, the voltage performance is no longer guaranteed to stay at the highest level. During dpu_kms_hw_init, calling dev_pm_opp_set_rate(dev, 0) drops the voltage, causing the MMCX rail to fall to MIN_SVS while the core clock is still at its maximum frequency. When the power is re-enabled, only the clock is enabled, leading to a situation where the MMCX rail is at MIN_SVS but the core clock is at its highest rate. In this state, the rail cannot sustain the clock rate, which may cause instability or system crash. Remove the call to dev_pm_opp_set_rate(dev, 0) from dpu_runtime_suspend to ensure the correct vote is restored when DPU resumes. Patchwork: https://patchwork.freedesktop.org/patch/710077/
INFO
Published Date :
June 24, 2026, 5:17 p.m.
Last Modified :
July 21, 2026, 5:29 p.m.
Remotely Exploit :
No
Source :
416baaa9-dc9f-4396-8d5f-8c081fb06d67
CVSS Scores
| Score | Version | Severity | Vector | Exploitability Score | Impact Score | Source |
|---|---|---|---|---|---|---|
| CVSS 3.1 | MEDIUM | [email protected] |
Solution
- Remove dev_pm_opp_set_rate(dev, 0) from dpu_runtime_suspend.
- Ensure core clock rate matches voltage performance.
- Apply kernel updates to resolve instability.
- Test system stability after applying changes.
References to Advisories, Solutions, and Tools
Here, you will find a curated list of external links that provide in-depth
information, practical solutions, and valuable tools related to
CVE-2026-53056.
CWE - Common Weakness Enumeration
While CVE identifies
specific instances of vulnerabilities, CWE categorizes the common flaws or
weaknesses that can lead to vulnerabilities. CVE-2026-53056 is
associated with the following CWEs:
Common Attack Pattern Enumeration and Classification (CAPEC)
Common Attack Pattern Enumeration and Classification
(CAPEC)
stores attack patterns, which are descriptions of the common attributes and
approaches employed by adversaries to exploit the CVE-2026-53056
weaknesses.
We scan GitHub repositories to detect new proof-of-concept exploits. Following list is a collection of public exploits and proof-of-concepts, which have been published on GitHub (sorted by the most recently updated).
Results are limited to the first 15 repositories due to potential performance issues.
The following list is the news that have been mention
CVE-2026-53056 vulnerability anywhere in the article.
The following table lists the changes that have been made to the
CVE-2026-53056 vulnerability over time.
Vulnerability history details can be useful for understanding the evolution of a vulnerability, and for identifying the most recent changes that may impact the vulnerability's severity, exploitability, or other characteristics.
-
Initial Analysis by [email protected]
Jul. 21, 2026
Action Type Old Value New Value Added CVSS V3.1 AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H Added CWE NVD-CWE-noinfo Added CPE Configuration OR *cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:* versions from (including) 6.2 up to (excluding) 6.6.141 *cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:* versions from (including) 6.7 up to (excluding) 6.12.91 *cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:* versions from (including) 6.13 up to (excluding) 6.18.33 *cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:* versions from (including) 6.19 up to (excluding) 7.0.10 *cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:* versions from (including) 5.9 up to (excluding) 6.1.175 Added Reference Type kernel.org: https://git.kernel.org/stable/c/0ccf4f27b4652570b5de3de02a89a86435559de9 Types: Patch Added Reference Type kernel.org: https://git.kernel.org/stable/c/0f7dd5839cfabaf9c007fb718ec66e907a473c93 Types: Patch Added Reference Type kernel.org: https://git.kernel.org/stable/c/1181a7028d37e0b1e720a36125a03f5db97e3d27 Types: Patch Added Reference Type kernel.org: https://git.kernel.org/stable/c/9830999c9e065c1813ec5435bfe4eab98ee54a87 Types: Patch Added Reference Type kernel.org: https://git.kernel.org/stable/c/bc1dccc518cc5ab5140fba06c27e7188e0ed342b Types: Patch Added Reference Type kernel.org: https://git.kernel.org/stable/c/c5735c7d0eef7a5240f9c1c66e44ba52a1be58d6 Types: Patch -
New CVE Received by 416baaa9-dc9f-4396-8d5f-8c081fb06d67
Jun. 24, 2026
Action Type Old Value New Value Added Affected [{'repo': 'https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git', 'vendor': 'Linux', 'product': 'Linux', 'versions': [{'status': 'affected', 'version': 'b0530eb1191307e9038d75e5c83973a396137681', 'lessThan': '1181a7028d37e0b1e720a36125a03f5db97e3d27', 'versionType': 'git'}, {'status': 'affected', 'version': 'b0530eb1191307e9038d75e5c83973a396137681', 'lessThan': '9830999c9e065c1813ec5435bfe4eab98ee54a87', 'versionType': 'git'}, {'status': 'affected', 'version': 'b0530eb1191307e9038d75e5c83973a396137681', 'lessThan': 'c5735c7d0eef7a5240f9c1c66e44ba52a1be58d6', 'versionType': 'git'}, {'status': 'affected', 'version': 'b0530eb1191307e9038d75e5c83973a396137681', 'lessThan': '0f7dd5839cfabaf9c007fb718ec66e907a473c93', 'versionType': 'git'}, {'status': 'affected', 'version': 'b0530eb1191307e9038d75e5c83973a396137681', 'lessThan': '0ccf4f27b4652570b5de3de02a89a86435559de9', 'versionType': 'git'}, {'status': 'affected', 'version': 'b0530eb1191307e9038d75e5c83973a396137681', 'lessThan': 'bc1dccc518cc5ab5140fba06c27e7188e0ed342b', 'versionType': 'git'}], 'programFiles': ['drivers/gpu/drm/msm/disp/dpu1/dpu_kms.c'], 'defaultStatus': 'unaffected'}, {'repo': 'https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git', 'vendor': 'Linux', 'product': 'Linux', 'versions': [{'status': 'affected', 'version': '5.9'}, {'status': 'unaffected', 'version': '0', 'lessThan': '5.9', 'versionType': 'semver'}, {'status': 'unaffected', 'version': '6.1.175', 'versionType': 'semver', 'lessThanOrEqual': '6.1.*'}, {'status': 'unaffected', 'version': '6.6.141', 'versionType': 'semver', 'lessThanOrEqual': '6.6.*'}, {'status': 'unaffected', 'version': '6.12.91', 'versionType': 'semver', 'lessThanOrEqual': '6.12.*'}, {'status': 'unaffected', 'version': '6.18.33', 'versionType': 'semver', 'lessThanOrEqual': '6.18.*'}, {'status': 'unaffected', 'version': '7.0.10', 'versionType': 'semver', 'lessThanOrEqual': '7.0.*'}, {'status': 'unaffected', 'version': '7.1', 'versionType': 'original_commit_for_fix', 'lessThanOrEqual': '*'}], 'programFiles': ['drivers/gpu/drm/msm/disp/dpu1/dpu_kms.c'], 'defaultStatus': 'affected'}] Added Description In the Linux kernel, the following vulnerability has been resolved: drm/msm/dpu: fix mismatch between power and frequency During DPU runtime suspend, calling dev_pm_opp_set_rate(dev, 0) drops the MMCX rail to MIN_SVS while the core clock frequency remains at its original (highest) rate. When runtime resume re-enables the clock, this may result in a mismatch between the rail voltage and the clock rate. For example, in the DPU bind path, the sequence could be: cpu0: dev_sync_state -> rpmhpd_sync_state cpu1: dpu_kms_hw_init timeline 0 ------------------------------------------------> t After rpmhpd_sync_state, the voltage performance is no longer guaranteed to stay at the highest level. During dpu_kms_hw_init, calling dev_pm_opp_set_rate(dev, 0) drops the voltage, causing the MMCX rail to fall to MIN_SVS while the core clock is still at its maximum frequency. When the power is re-enabled, only the clock is enabled, leading to a situation where the MMCX rail is at MIN_SVS but the core clock is at its highest rate. In this state, the rail cannot sustain the clock rate, which may cause instability or system crash. Remove the call to dev_pm_opp_set_rate(dev, 0) from dpu_runtime_suspend to ensure the correct vote is restored when DPU resumes. Patchwork: https://patchwork.freedesktop.org/patch/710077/ Added Reference https://git.kernel.org/stable/c/0ccf4f27b4652570b5de3de02a89a86435559de9 Added Reference https://git.kernel.org/stable/c/0f7dd5839cfabaf9c007fb718ec66e907a473c93 Added Reference https://git.kernel.org/stable/c/1181a7028d37e0b1e720a36125a03f5db97e3d27 Added Reference https://git.kernel.org/stable/c/9830999c9e065c1813ec5435bfe4eab98ee54a87 Added Reference https://git.kernel.org/stable/c/bc1dccc518cc5ab5140fba06c27e7188e0ed342b Added Reference https://git.kernel.org/stable/c/c5735c7d0eef7a5240f9c1c66e44ba52a1be58d6