drm/vc4: Use managed KMS polling to fix UAF on unbind
Summary
| CVE | CVE-2026-98309 |
| State | PUBLISHED |
| Assigner | Linux |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2026-10-06 09:18:22 UTC |
| Updated | 2026-10-06 09:18:22 UTC |
| Description | In the Linux kernel, the following vulnerability has been resolved:
drm/vc4: Use managed KMS polling to fix UAF on unbind
vc4_kms_load() calls drm_kms_helper_poll_init() but the driver provides
no matching drm_kms_helper_poll_fini(). The output poll work stays
scheduled after unbind and runs on the freed drm_device:
# modprobe vc4; rmmod vc4; sleep 10
BUG: KASAN: slab-use-after-free in delayed_work_timer_fn
BUG: KASAN: slab-use-after-free in drm_client_dev_hotplug [drm]
Workqueue: events output_poll_execute [drm_kms_helper]
Allocated by task 171: __devm_drm_dev_alloc
Freed by task 262 (rmmod): drm_dev_put / component_del
Use drmm_kms_helper_poll_init() so polling is finalized with the device,
as other drivers do. |
Vendor Declared Affected Products
| Source | Vendor | Product | Version | Platforms |
|---|
| CNA |
Linux |
Linux |
affected c8b75bca92cbf064b9fa125fc74a85994452e935 b6beee927e7f4e3142032ff91b2d0417cdddc0f6 git |
Not specified |
| CNA |
Linux |
Linux |
affected c8b75bca92cbf064b9fa125fc74a85994452e935 cf0c4432bda37b02e7d430ff5017228ceb7caf0c git |
Not specified |
| CNA |
Linux |
Linux |
affected c8b75bca92cbf064b9fa125fc74a85994452e935 ee507691c18f9fee5d4751e295ab9a7ff31d59ae git |
Not specified |
| CNA |
Linux |
Linux |
affected c8b75bca92cbf064b9fa125fc74a85994452e935 7f9780df677370a19b4ec9764f13b1b82073e0d9 git |
Not specified |
| CNA |
Linux |
Linux |
affected c8b75bca92cbf064b9fa125fc74a85994452e935 073a30d75f309812ed61af134f24ffef4107b13a git |
Not specified |
| CNA |
Linux |
Linux |
affected 4.4 |
Not specified |
| CNA |
Linux |
Linux |
unaffected 4.4 semver |
Not specified |
| CNA |
Linux |
Linux |
unaffected 6.6.158 6.6.* semver |
Not specified |
| CNA |
Linux |
Linux |
unaffected 6.12.112 6.12.* semver |
Not specified |
| CNA |
Linux |
Linux |
unaffected 6.18.54 6.18.* semver |
Not specified |
| CNA |
Linux |
Linux |
unaffected 7.2.8 7.2.* semver |
Not specified |
| CNA |
Linux |
Linux |
unaffected 7.3-rc4 * original_commit_for_fix |
Not specified |
References
| Reference | Source | Link | Tags |
|---|
| git.kernel.org/stable/c/ee507691c18f9fee5d4751e295ab9a7ff31d59ae |
416baaa9-dc9f-4396-8d5f-8c081fb06d67 |
git.kernel.org |
|
| git.kernel.org/stable/c/7f9780df677370a19b4ec9764f13b1b82073e0d9 |
416baaa9-dc9f-4396-8d5f-8c081fb06d67 |
git.kernel.org |
|
| git.kernel.org/stable/c/073a30d75f309812ed61af134f24ffef4107b13a |
416baaa9-dc9f-4396-8d5f-8c081fb06d67 |
git.kernel.org |
|
| git.kernel.org/stable/c/cf0c4432bda37b02e7d430ff5017228ceb7caf0c |
416baaa9-dc9f-4396-8d5f-8c081fb06d67 |
git.kernel.org |
|
| git.kernel.org/stable/c/b6beee927e7f4e3142032ff91b2d0417cdddc0f6 |
416baaa9-dc9f-4396-8d5f-8c081fb06d67 |
git.kernel.org |
|
| CVE Program record |
CVE.ORG |
www.cve.org |
canonical |
| NVD vulnerability detail |
NVD |
nvd.nist.gov |
canonical, analysis |
No vendor comments have been submitted for this CVE.
There are currently no legacy QID mappings associated with this CVE.