{"api_version":"1","generated_at":"2026-10-06T22:59:45+00:00","cve":"CVE-2026-98313","urls":{"html":"https://cve.report/CVE-2026-98313","api":"https://cve.report/api/cve/CVE-2026-98313.json","docs":"https://cve.report/api","cve_org":"https://www.cve.org/CVERecord?id=CVE-2026-98313","nvd":"https://nvd.nist.gov/vuln/detail/CVE-2026-98313"},"summary":{"title":"drm/msm/dp: skip PUSH_IDLE when the link was never enabled","description":"In the Linux kernel, the following vulnerability has been resolved:\n\ndrm/msm/dp: skip PUSH_IDLE when the link was never enabled\n\nmsm_dp_display_atomic_enable() returns early when link training fails,\nleaving ->power_on false and the main link down.\nmsm_dp_display_atomic_disable() nevertheless writes DP_STATE_CTRL_PUSH_IDLE\nand waits for an idle-pattern completion that cannot arrive, so every failed\nenable is followed by \"PUSH_IDLE pattern timedout\".\n\nEvery other step of the teardown is already gated on that flag:\nmsm_dp_display_disable(), called from .atomic_post_disable(), returns early\non !power_on. The PUSH_IDLE write is the only one that is not, so the\ncontroller's runtime-PM reference is then dropped without the link having\nbeen taken down.\n\nOn glymur (Snapdragon X2 Elite) the consequence is not a warning. The SoC\ndoes not survive it: TrustZone force-stops the SOCCP and ADSP remote\nprocessors and the machine resets silently about 50 ms later, with no oops\nand no panic. On an ASUS Zenbook A16 (UX3607OA), whose eDP panel does not\ncurrently train, this reproduces without any compositor or GPU involvement:\n\n  # eDP enable has already failed with \"Failed link training (rc=-104)\"\n  echo 1 > /sys/class/graphics/fb0/blank\n\n  [535.645455] === marker ===\n  [535.694833] qcom_q6v5_pas d00000.remoteproc: fatal error received: \\\n                 sys_m_smsm.c:512:TZ force stop\n  [535.694875] remoteproc remoteproc0: crash detected in soccp: type fatal error\n  [535.728857] qcom_q6v5_pas 6800000.remoteproc: fatal error received: \\\n                 sys_m_smsm.c:783:err fatal notification received from TZ\n  <SoC reset>\n\nGate the PUSH_IDLE write on ->power_on so the disable path is consistent\nwith the rest of the teardown. With this applied the same sequence is\nharmless and the machine stays up; without it, it resets every time.\n\nThe unconditional write dates back to the original DP driver\n(c943b4948b58 (\"drm/msm/dp: add displayPort driver support\")), but the\nsurrounding code has been restructured several times since, so no Fixes:\ntag is offered.\n\nNote that the eDP link-training failure that exposes this on the A16 is a\nseparate problem in the glymur eDP PHY and is reported separately; this\nchange is about not damaging the machine when training fails, for whatever\nreason.\n\nTested on ASUS Zenbook A16 (UX3607OA), Snapdragon X2 Elite Extreme, on\nlinux-next next-20260803 and next-20260807. The machine has since been\nrunning next-20260807 with this patch as its daily driver.\n\nPatchwork: https://patchwork.freedesktop.org/patch/745167/","state":"PUBLISHED","assigner":"Linux","published_at":"2026-10-06 09:18:22","updated_at":"2026-10-06 09:18:22"},"problem_types":[],"metrics":[],"references":[{"url":"https://git.kernel.org/stable/c/dc57147549a10c99766144cde265645287718ff7","name":"https://git.kernel.org/stable/c/dc57147549a10c99766144cde265645287718ff7","refsource":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","tags":[],"title":"","mime":"","httpstatus":"","archivestatus":"0"},{"url":"https://git.kernel.org/stable/c/e249a6e2a130c08bb4d8b0a55cbe29754307e5c9","name":"https://git.kernel.org/stable/c/e249a6e2a130c08bb4d8b0a55cbe29754307e5c9","refsource":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","tags":[],"title":"","mime":"","httpstatus":"","archivestatus":"0"},{"url":"https://git.kernel.org/stable/c/5e97d117b79c3ce89542369ef697be64850de8ad","name":"https://git.kernel.org/stable/c/5e97d117b79c3ce89542369ef697be64850de8ad","refsource":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","tags":[],"title":"","mime":"","httpstatus":"","archivestatus":"0"},{"url":"https://www.cve.org/CVERecord?id=CVE-2026-98313","name":"CVE Program record","refsource":"CVE.ORG","tags":["canonical"]},{"url":"https://nvd.nist.gov/vuln/detail/CVE-2026-98313","name":"NVD vulnerability detail","refsource":"NVD","tags":["canonical","analysis"]}],"affected":[{"source":"CNA","vendor":"Linux","product":"Linux","version":"affected 1da177e4c3f41524e886b7f1b8a0c1fc7321cac2 dc57147549a10c99766144cde265645287718ff7 git","platforms":[]},{"source":"CNA","vendor":"Linux","product":"Linux","version":"affected 1da177e4c3f41524e886b7f1b8a0c1fc7321cac2 5e97d117b79c3ce89542369ef697be64850de8ad git","platforms":[]},{"source":"CNA","vendor":"Linux","product":"Linux","version":"affected 1da177e4c3f41524e886b7f1b8a0c1fc7321cac2 e249a6e2a130c08bb4d8b0a55cbe29754307e5c9 git","platforms":[]},{"source":"CNA","vendor":"Linux","product":"Linux","version":"affected 6.18.54 semver","platforms":[]},{"source":"CNA","vendor":"Linux","product":"Linux","version":"affected 7.2.8 semver","platforms":[]},{"source":"CNA","vendor":"Linux","product":"Linux","version":"unaffected 6.18.54 6.18.* semver","platforms":[]},{"source":"CNA","vendor":"Linux","product":"Linux","version":"unaffected 7.2.8 7.2.* semver","platforms":[]},{"source":"CNA","vendor":"Linux","product":"Linux","version":"unaffected 7.3-rc4 * original_commit_for_fix","platforms":[]}],"timeline":[],"solutions":[],"workarounds":[],"exploits":[],"credits":[],"nvd_cpes":[],"vendor_comments":[],"enrichments":{"kev":null,"epss":null,"legacy_qids":[]},"source_records":{"cve_program":{"containers":{"cna":{"affected":[{"defaultStatus":"unaffected","product":"Linux","programFiles":["drivers/gpu/drm/msm/dp/dp_display.c"],"repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","vendor":"Linux","versions":[{"lessThan":"dc57147549a10c99766144cde265645287718ff7","status":"affected","version":"1da177e4c3f41524e886b7f1b8a0c1fc7321cac2","versionType":"git"},{"lessThan":"5e97d117b79c3ce89542369ef697be64850de8ad","status":"affected","version":"1da177e4c3f41524e886b7f1b8a0c1fc7321cac2","versionType":"git"},{"lessThan":"e249a6e2a130c08bb4d8b0a55cbe29754307e5c9","status":"affected","version":"1da177e4c3f41524e886b7f1b8a0c1fc7321cac2","versionType":"git"},{"lessThan":"6.18.54","status":"affected","version":"0","versionType":"semver"},{"lessThan":"7.2.8","status":"affected","version":"0","versionType":"semver"}]},{"defaultStatus":"affected","product":"Linux","programFiles":["drivers/gpu/drm/msm/dp/dp_display.c"],"repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","vendor":"Linux","versions":[{"lessThanOrEqual":"6.18.*","status":"unaffected","version":"6.18.54","versionType":"semver"},{"lessThanOrEqual":"7.2.*","status":"unaffected","version":"7.2.8","versionType":"semver"},{"lessThanOrEqual":"*","status":"unaffected","version":"7.3-rc4","versionType":"original_commit_for_fix"}]}],"cpeApplicability":[{"nodes":[{"cpeMatch":[{"criteria":"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*","versionEndExcluding":"6.18.54","vulnerable":true},{"criteria":"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*","versionEndExcluding":"7.2.8","vulnerable":true},{"criteria":"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*","versionEndExcluding":"7.3-rc4","vulnerable":true}],"negate":false,"operator":"OR"}]}],"descriptions":[{"lang":"en","value":"In the Linux kernel, the following vulnerability has been resolved:\n\ndrm/msm/dp: skip PUSH_IDLE when the link was never enabled\n\nmsm_dp_display_atomic_enable() returns early when link training fails,\nleaving ->power_on false and the main link down.\nmsm_dp_display_atomic_disable() nevertheless writes DP_STATE_CTRL_PUSH_IDLE\nand waits for an idle-pattern completion that cannot arrive, so every failed\nenable is followed by \"PUSH_IDLE pattern timedout\".\n\nEvery other step of the teardown is already gated on that flag:\nmsm_dp_display_disable(), called from .atomic_post_disable(), returns early\non !power_on. The PUSH_IDLE write is the only one that is not, so the\ncontroller's runtime-PM reference is then dropped without the link having\nbeen taken down.\n\nOn glymur (Snapdragon X2 Elite) the consequence is not a warning. The SoC\ndoes not survive it: TrustZone force-stops the SOCCP and ADSP remote\nprocessors and the machine resets silently about 50 ms later, with no oops\nand no panic. On an ASUS Zenbook A16 (UX3607OA), whose eDP panel does not\ncurrently train, this reproduces without any compositor or GPU involvement:\n\n  # eDP enable has already failed with \"Failed link training (rc=-104)\"\n  echo 1 > /sys/class/graphics/fb0/blank\n\n  [535.645455] === marker ===\n  [535.694833] qcom_q6v5_pas d00000.remoteproc: fatal error received: \\\n                 sys_m_smsm.c:512:TZ force stop\n  [535.694875] remoteproc remoteproc0: crash detected in soccp: type fatal error\n  [535.728857] qcom_q6v5_pas 6800000.remoteproc: fatal error received: \\\n                 sys_m_smsm.c:783:err fatal notification received from TZ\n  <SoC reset>\n\nGate the PUSH_IDLE write on ->power_on so the disable path is consistent\nwith the rest of the teardown. With this applied the same sequence is\nharmless and the machine stays up; without it, it resets every time.\n\nThe unconditional write dates back to the original DP driver\n(c943b4948b58 (\"drm/msm/dp: add displayPort driver support\")), but the\nsurrounding code has been restructured several times since, so no Fixes:\ntag is offered.\n\nNote that the eDP link-training failure that exposes this on the A16 is a\nseparate problem in the glymur eDP PHY and is reported separately; this\nchange is about not damaging the machine when training fails, for whatever\nreason.\n\nTested on ASUS Zenbook A16 (UX3607OA), Snapdragon X2 Elite Extreme, on\nlinux-next next-20260803 and next-20260807. The machine has since been\nrunning next-20260807 with this patch as its daily driver.\n\nPatchwork: https://patchwork.freedesktop.org/patch/745167/"}],"providerMetadata":{"dateUpdated":"2026-10-06T08:46:09.174Z","orgId":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","shortName":"Linux"},"references":[{"url":"https://git.kernel.org/stable/c/dc57147549a10c99766144cde265645287718ff7"},{"url":"https://git.kernel.org/stable/c/5e97d117b79c3ce89542369ef697be64850de8ad"},{"url":"https://git.kernel.org/stable/c/e249a6e2a130c08bb4d8b0a55cbe29754307e5c9"}],"title":"drm/msm/dp: skip PUSH_IDLE when the link was never enabled","x_generator":{"engine":"bippy-1.2.0"}}},"cveMetadata":{"assignerOrgId":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","assignerShortName":"Linux","cveId":"CVE-2026-98313","datePublished":"2026-10-06T08:46:09.174Z","dateReserved":"2026-09-25T10:25:14.339Z","dateUpdated":"2026-10-06T08:46:09.174Z","state":"PUBLISHED"},"dataType":"CVE_RECORD","dataVersion":"5.2"},"nvd":{"publishedDate":"2026-10-06 09:18:22","lastModifiedDate":"2026-10-06 09:18:22","problem_types":[],"metrics":[],"configurations":[]},"legacy_mitre":{"record":{"CveYear":"2026","CveId":"98313","Ordinal":"1","Title":"drm/msm/dp: skip PUSH_IDLE when the link was never enabled","CVE":"CVE-2026-98313","Year":"2026"},"notes":[{"CveYear":"2026","CveId":"98313","Ordinal":"1","NoteData":"In the Linux kernel, the following vulnerability has been resolved:\n\ndrm/msm/dp: skip PUSH_IDLE when the link was never enabled\n\nmsm_dp_display_atomic_enable() returns early when link training fails,\nleaving ->power_on false and the main link down.\nmsm_dp_display_atomic_disable() nevertheless writes DP_STATE_CTRL_PUSH_IDLE\nand waits for an idle-pattern completion that cannot arrive, so every failed\nenable is followed by \"PUSH_IDLE pattern timedout\".\n\nEvery other step of the teardown is already gated on that flag:\nmsm_dp_display_disable(), called from .atomic_post_disable(), returns early\non !power_on. The PUSH_IDLE write is the only one that is not, so the\ncontroller's runtime-PM reference is then dropped without the link having\nbeen taken down.\n\nOn glymur (Snapdragon X2 Elite) the consequence is not a warning. The SoC\ndoes not survive it: TrustZone force-stops the SOCCP and ADSP remote\nprocessors and the machine resets silently about 50 ms later, with no oops\nand no panic. On an ASUS Zenbook A16 (UX3607OA), whose eDP panel does not\ncurrently train, this reproduces without any compositor or GPU involvement:\n\n  # eDP enable has already failed with \"Failed link training (rc=-104)\"\n  echo 1 > /sys/class/graphics/fb0/blank\n\n  [535.645455] === marker ===\n  [535.694833] qcom_q6v5_pas d00000.remoteproc: fatal error received: \\\n                 sys_m_smsm.c:512:TZ force stop\n  [535.694875] remoteproc remoteproc0: crash detected in soccp: type fatal error\n  [535.728857] qcom_q6v5_pas 6800000.remoteproc: fatal error received: \\\n                 sys_m_smsm.c:783:err fatal notification received from TZ\n  <SoC reset>\n\nGate the PUSH_IDLE write on ->power_on so the disable path is consistent\nwith the rest of the teardown. With this applied the same sequence is\nharmless and the machine stays up; without it, it resets every time.\n\nThe unconditional write dates back to the original DP driver\n(c943b4948b58 (\"drm/msm/dp: add displayPort driver support\")), but the\nsurrounding code has been restructured several times since, so no Fixes:\ntag is offered.\n\nNote that the eDP link-training failure that exposes this on the A16 is a\nseparate problem in the glymur eDP PHY and is reported separately; this\nchange is about not damaging the machine when training fails, for whatever\nreason.\n\nTested on ASUS Zenbook A16 (UX3607OA), Snapdragon X2 Elite Extreme, on\nlinux-next next-20260803 and next-20260807. The machine has since been\nrunning next-20260807 with this patch as its daily driver.\n\nPatchwork: https://patchwork.freedesktop.org/patch/745167/","Type":"Description","Title":"drm/msm/dp: skip PUSH_IDLE when the link was never enabled"}]}}}