{"id":"CVE-2026-98313","title":"In the Linux kernel, the following vulnerability has been resolved:\n\ndrm/msm/dp: skip PUSH_IDLE when the link was never enabled\n\nmsm_dp_display_atomic_enable() returns early when link training fails,\nleaving ->power_on false and the main…","summary":"In the Linux kernel, the following vulnerability has been resolved:\n\ndrm/msm/dp: skip PUSH_IDLE when the link was never enabled\n\nmsm_dp_display_atomic_enable() returns early when link training fails,\nleaving ->power_on false and the main…","severity":"none","vendor":"Linux","product":"Linux","affected":["Linux >= 1da177e4c3f41524e886b7f1b8a0c1fc7321cac2 < dc57147549a10c99766144cde265645287718ff7","Linux >= 1da177e4c3f41524e886b7f1b8a0c1fc7321cac2 < 5e97d117b79c3ce89542369ef697be64850de8ad","Linux >= 1da177e4c3f41524e886b7f1b8a0c1fc7321cac2 < e249a6e2a130c08bb4d8b0a55cbe29754307e5c9","Linux < 6.18.54","Linux < 7.2.8","Linux (all versions)"],"published":"2026-10-06","updated":"2026-10-06","sourceUpdated":"2026-10-06T09:18:22.887","source":"NVD","sourceUrl":"https://nvd.nist.gov/vuln/detail/CVE-2026-98313","references":[{"url":"https://git.kernel.org/stable/c/5e97d117b79c3ce89542369ef697be64850de8ad","label":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/dc57147549a10c99766144cde265645287718ff7","label":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/e249a6e2a130c08bb4d8b0a55cbe29754307e5c9","label":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"}],"tags":["nvd","cve.org"],"ingestedAt":"2026-10-06T08:50:17.410Z","slug":"CVE-2026-98313","body":"## Overview\n\nIn the Linux kernel, the following vulnerability has been resolved:\n\ndrm/msm/dp: skip PUSH_IDLE when the link was never enabled\n\nmsm_dp_display_atomic_enable() returns early when link training fails,\nleaving ->power_on false and the main link down.\nmsm_dp_display_atomic_disable() nevertheless writes DP_STATE_CTRL_PUSH_IDLE\nand waits for an idle-pattern completion that cannot arrive, so every failed\nenable is followed by \"PUSH_IDLE pattern timedout\".\n\nEvery other step of the teardown is already gated on that flag:\nmsm_dp_display_disable(), called from .atomic_post_disable(), returns early\non !power_on. The PUSH_IDLE write is the only one that is not, so the\ncontroller's runtime-PM reference is then dropped without the link having\nbeen taken down.\n\nOn glymur (Snapdragon X2 Elite) the consequence is not a warning. The SoC\ndoes not survive it: TrustZone force-stops the SOCCP and ADSP remote\nprocessors and the machine resets silently about 50 ms later, with no oops\nand no panic. On an ASUS Zenbook A16 (UX3607OA), whose eDP panel does not\ncurrently train, this reproduces without any compositor or GPU involvement:\n\n  # eDP enable has already failed with \"Failed link training (rc=-104)\"\n  echo 1 > /sys/class/graphics/fb0/blank\n\n  [535.645455] === marker ===\n  [535.694833] qcom_q6v5_pas d00000.remoteproc: fatal error received: \\\n                 sys_m_smsm.c:512:TZ force stop\n  [535.694875] remoteproc remoteproc0: crash detected in soccp: type fatal error\n  [535.728857] qcom_q6v5_pas 6800000.remoteproc: fatal error received: \\\n                 sys_m_smsm.c:783:err fatal notification received from TZ\n  <SoC reset>\n\nGate the PUSH_IDLE write on ->power_on so the disable path is consistent\nwith the rest of the teardown. With this applied the same sequence is\nharmless and the machine stays up; without it, it resets every time.\n\nThe unconditional write dates back to the original DP driver\n(c943b4948b58 (\"drm/msm/dp: add displayPort driver support\")), but the\nsurrounding code has been restructured several times since, so no Fixes:\ntag is offered.\n\nNote that the eDP link-training failure that exposes this on the A16 is a\nseparate problem in the glymur eDP PHY and is reported separately; this\nchange is about not damaging the machine when training fails, for whatever\nreason.\n\nTested on ASUS Zenbook A16 (UX3607OA), Snapdragon X2 Elite Extreme, on\nlinux-next next-20260803 and next-20260807. The machine has since been\nrunning next-20260807 with this patch as its daily driver.\n\nPatchwork: https://patchwork.freedesktop.org/patch/745167/\n\n## Remediation\n\nRefer to the linked advisories for vendor-supplied fixes and affected version ranges.","depth":"sunlit","depthScore":3,"depthScoreParts":{"impact":2.8,"likelihood":0,"exploitation":0,"ransomware":0},"changes":[]}