{"api_version":"1","generated_at":"2026-09-18T17:56:32+00:00","cve":"CVE-2026-93194","urls":{"html":"https://cve.report/CVE-2026-93194","api":"https://cve.report/api/cve/CVE-2026-93194.json","docs":"https://cve.report/api","cve_org":"https://www.cve.org/CVERecord?id=CVE-2026-93194","nvd":"https://nvd.nist.gov/vuln/detail/CVE-2026-93194"},"summary":{"title":"drm/rockchip: dw_dp: Release core resources","description":"In the Linux kernel, the following vulnerability has been resolved:\n\ndrm/rockchip: dw_dp: Release core resources\n\nCore resources such as the DisplayPort AUX channel get initialized and\nregistered during dw_dp_bind(), but are never unregistered, which may\nlead to memory leaks and/or use-after-free:\n\n[  224.661371] BUG: KASAN: slab-use-after-free in device_is_dependent+0xe0/0x2b0\n[  224.662015] Read of size 8 at addr ffff00011aee8550 by task modprobe/658\n[  224.662612]\n[  224.662752] CPU: 7 UID: 0 PID: 658 Comm: modprobe Not tainted 7.0.0-rc2-next-20260305 #14 PREEMPT\n[  224.662759] Hardware name: Radxa ROCK 5B (DT)\n[  224.662762] Call trace:\n[  224.662764]  show_stack+0x20/0x38 (C)\n[  224.662772]  dump_stack_lvl+0x6c/0x98\n[  224.662777]  print_report+0x160/0x4b8\n[  224.662783]  kasan_report+0xb4/0xe0\n[  224.662790]  __asan_report_load8_noabort+0x20/0x30\n[  224.662796]  device_is_dependent+0xe0/0x2b0\n[  224.662802]  device_is_dependent+0x108/0x2b0\n[  224.662808]  device_link_add+0x1f8/0x10b0\n[  224.662813]  devm_of_phy_get_by_index+0x120/0x200\n[  224.662819]  dw_dp_bind+0x34c/0xb10 [dw_dp]\n[  224.662830]  dw_dp_rockchip_bind+0x194/0x250 [rockchipdrm]\n[  224.662864]  component_bind_all+0x3a8/0x720\n[  224.662869]  rockchip_drm_bind+0x120/0x390 [rockchipdrm]\n[  224.662899]  try_to_bring_up_aggregate_device+0x76c/0x838\n[  224.662904]  component_master_add_with_match+0x1f4/0x230\n[  224.662909]  rockchip_drm_platform_probe+0x420/0x538 [rockchipdrm]\n[  224.662939]  platform_probe+0xe8/0x168\n[  224.662945]  really_probe+0x340/0x828\n[  224.662950]  __driver_probe_device+0x2e0/0x350\n[  224.662954]  driver_probe_device+0x80/0x140\n[  224.662959]  __driver_attach+0x398/0x460\n[  224.662964]  bus_for_each_dev+0xe0/0x198\n[  224.662968]  driver_attach+0x50/0x68\n[  224.662972]  bus_add_driver+0x2a0/0x4c0\n[  224.662977]  driver_register+0x294/0x360\n[  224.662982]  __platform_driver_register+0x7c/0x98\n[  224.662987]  rockchip_drm_init+0xc4/0xff8 [rockchipdrm]\n\nSince a previous commit exported dw_dp_unbind() function in DW DP core\nlibrary to take care of the necessary cleanup, use this in the\ncomponent's unbind() callback, as well as in its bind() error path.","state":"PUBLISHED","assigner":"Linux","published_at":"2026-09-17 17:18:15","updated_at":"2026-09-17 17:18:15"},"problem_types":[],"metrics":[],"references":[{"url":"https://git.kernel.org/stable/c/11f07929f454ecc2c5d0da3a4727fd205be43e49","name":"https://git.kernel.org/stable/c/11f07929f454ecc2c5d0da3a4727fd205be43e49","refsource":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","tags":[],"title":"","mime":"","httpstatus":"","archivestatus":"0"},{"url":"https://git.kernel.org/stable/c/362e005b816ee8052a195b98d845966689b398a1","name":"https://git.kernel.org/stable/c/362e005b816ee8052a195b98d845966689b398a1","refsource":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","tags":[],"title":"","mime":"","httpstatus":"","archivestatus":"0"},{"url":"https://git.kernel.org/stable/c/cc6d7aca2f37a1525a94ef97eb3ce361732c876c","name":"https://git.kernel.org/stable/c/cc6d7aca2f37a1525a94ef97eb3ce361732c876c","refsource":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","tags":[],"title":"","mime":"","httpstatus":"","archivestatus":"0"},{"url":"https://www.cve.org/CVERecord?id=CVE-2026-93194","name":"CVE Program record","refsource":"CVE.ORG","tags":["canonical"]},{"url":"https://nvd.nist.gov/vuln/detail/CVE-2026-93194","name":"NVD vulnerability detail","refsource":"NVD","tags":["canonical","analysis"]}],"affected":[{"source":"CNA","vendor":"Linux","product":"Linux","version":"affected d68ba7bac9555d05e2f5b310c898b2a5c7eff174 362e005b816ee8052a195b98d845966689b398a1 git","platforms":[]},{"source":"CNA","vendor":"Linux","product":"Linux","version":"affected d68ba7bac9555d05e2f5b310c898b2a5c7eff174 11f07929f454ecc2c5d0da3a4727fd205be43e49 git","platforms":[]},{"source":"CNA","vendor":"Linux","product":"Linux","version":"affected d68ba7bac9555d05e2f5b310c898b2a5c7eff174 cc6d7aca2f37a1525a94ef97eb3ce361732c876c git","platforms":[]},{"source":"CNA","vendor":"Linux","product":"Linux","version":"affected 6.18","platforms":[]},{"source":"CNA","vendor":"Linux","product":"Linux","version":"unaffected 6.18 semver","platforms":[]},{"source":"CNA","vendor":"Linux","product":"Linux","version":"unaffected 6.18.52 6.18.* semver","platforms":[]},{"source":"CNA","vendor":"Linux","product":"Linux","version":"unaffected 7.2.6 7.2.* semver","platforms":[]},{"source":"CNA","vendor":"Linux","product":"Linux","version":"unaffected 7.3-rc1 * original_commit_for_fix","platforms":[]}],"timeline":[],"solutions":[],"workarounds":[],"exploits":[],"credits":[],"nvd_cpes":[],"vendor_comments":[],"enrichments":{"kev":null,"epss":null,"legacy_qids":[]},"source_records":{"cve_program":{"containers":{"cna":{"affected":[{"defaultStatus":"unaffected","product":"Linux","programFiles":["drivers/gpu/drm/rockchip/dw_dp-rockchip.c"],"repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","vendor":"Linux","versions":[{"lessThan":"362e005b816ee8052a195b98d845966689b398a1","status":"affected","version":"d68ba7bac9555d05e2f5b310c898b2a5c7eff174","versionType":"git"},{"lessThan":"11f07929f454ecc2c5d0da3a4727fd205be43e49","status":"affected","version":"d68ba7bac9555d05e2f5b310c898b2a5c7eff174","versionType":"git"},{"lessThan":"cc6d7aca2f37a1525a94ef97eb3ce361732c876c","status":"affected","version":"d68ba7bac9555d05e2f5b310c898b2a5c7eff174","versionType":"git"}]},{"defaultStatus":"affected","product":"Linux","programFiles":["drivers/gpu/drm/rockchip/dw_dp-rockchip.c"],"repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","vendor":"Linux","versions":[{"status":"affected","version":"6.18"},{"lessThan":"6.18","status":"unaffected","version":"0","versionType":"semver"},{"lessThanOrEqual":"6.18.*","status":"unaffected","version":"6.18.52","versionType":"semver"},{"lessThanOrEqual":"7.2.*","status":"unaffected","version":"7.2.6","versionType":"semver"},{"lessThanOrEqual":"*","status":"unaffected","version":"7.3-rc1","versionType":"original_commit_for_fix"}]}],"cpeApplicability":[{"nodes":[{"cpeMatch":[{"criteria":"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*","versionEndExcluding":"6.18.52","versionStartIncluding":"6.18","vulnerable":true},{"criteria":"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*","versionEndExcluding":"7.2.6","versionStartIncluding":"6.18","vulnerable":true},{"criteria":"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*","versionEndExcluding":"7.3-rc1","versionStartIncluding":"6.18","vulnerable":true}],"negate":false,"operator":"OR"}]}],"descriptions":[{"lang":"en","value":"In the Linux kernel, the following vulnerability has been resolved:\n\ndrm/rockchip: dw_dp: Release core resources\n\nCore resources such as the DisplayPort AUX channel get initialized and\nregistered during dw_dp_bind(), but are never unregistered, which may\nlead to memory leaks and/or use-after-free:\n\n[  224.661371] BUG: KASAN: slab-use-after-free in device_is_dependent+0xe0/0x2b0\n[  224.662015] Read of size 8 at addr ffff00011aee8550 by task modprobe/658\n[  224.662612]\n[  224.662752] CPU: 7 UID: 0 PID: 658 Comm: modprobe Not tainted 7.0.0-rc2-next-20260305 #14 PREEMPT\n[  224.662759] Hardware name: Radxa ROCK 5B (DT)\n[  224.662762] Call trace:\n[  224.662764]  show_stack+0x20/0x38 (C)\n[  224.662772]  dump_stack_lvl+0x6c/0x98\n[  224.662777]  print_report+0x160/0x4b8\n[  224.662783]  kasan_report+0xb4/0xe0\n[  224.662790]  __asan_report_load8_noabort+0x20/0x30\n[  224.662796]  device_is_dependent+0xe0/0x2b0\n[  224.662802]  device_is_dependent+0x108/0x2b0\n[  224.662808]  device_link_add+0x1f8/0x10b0\n[  224.662813]  devm_of_phy_get_by_index+0x120/0x200\n[  224.662819]  dw_dp_bind+0x34c/0xb10 [dw_dp]\n[  224.662830]  dw_dp_rockchip_bind+0x194/0x250 [rockchipdrm]\n[  224.662864]  component_bind_all+0x3a8/0x720\n[  224.662869]  rockchip_drm_bind+0x120/0x390 [rockchipdrm]\n[  224.662899]  try_to_bring_up_aggregate_device+0x76c/0x838\n[  224.662904]  component_master_add_with_match+0x1f4/0x230\n[  224.662909]  rockchip_drm_platform_probe+0x420/0x538 [rockchipdrm]\n[  224.662939]  platform_probe+0xe8/0x168\n[  224.662945]  really_probe+0x340/0x828\n[  224.662950]  __driver_probe_device+0x2e0/0x350\n[  224.662954]  driver_probe_device+0x80/0x140\n[  224.662959]  __driver_attach+0x398/0x460\n[  224.662964]  bus_for_each_dev+0xe0/0x198\n[  224.662968]  driver_attach+0x50/0x68\n[  224.662972]  bus_add_driver+0x2a0/0x4c0\n[  224.662977]  driver_register+0x294/0x360\n[  224.662982]  __platform_driver_register+0x7c/0x98\n[  224.662987]  rockchip_drm_init+0xc4/0xff8 [rockchipdrm]\n\nSince a previous commit exported dw_dp_unbind() function in DW DP core\nlibrary to take care of the necessary cleanup, use this in the\ncomponent's unbind() callback, as well as in its bind() error path."}],"providerMetadata":{"dateUpdated":"2026-09-17T16:12:17.802Z","orgId":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","shortName":"Linux"},"references":[{"url":"https://git.kernel.org/stable/c/362e005b816ee8052a195b98d845966689b398a1"},{"url":"https://git.kernel.org/stable/c/11f07929f454ecc2c5d0da3a4727fd205be43e49"},{"url":"https://git.kernel.org/stable/c/cc6d7aca2f37a1525a94ef97eb3ce361732c876c"}],"title":"drm/rockchip: dw_dp: Release core resources","x_generator":{"engine":"bippy-1.2.0"}}},"cveMetadata":{"assignerOrgId":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","assignerShortName":"Linux","cveId":"CVE-2026-93194","datePublished":"2026-09-17T16:12:17.802Z","dateReserved":"2026-09-17T16:02:15.092Z","dateUpdated":"2026-09-17T16:12:17.802Z","state":"PUBLISHED"},"dataType":"CVE_RECORD","dataVersion":"5.2"},"nvd":{"publishedDate":"2026-09-17 17:18:15","lastModifiedDate":"2026-09-17 17:18:15","problem_types":[],"metrics":[],"configurations":[]},"legacy_mitre":{"record":{"CveYear":"2026","CveId":"93194","Ordinal":"1","Title":"drm/rockchip: dw_dp: Release core resources","CVE":"CVE-2026-93194","Year":"2026"},"notes":[{"CveYear":"2026","CveId":"93194","Ordinal":"1","NoteData":"In the Linux kernel, the following vulnerability has been resolved:\n\ndrm/rockchip: dw_dp: Release core resources\n\nCore resources such as the DisplayPort AUX channel get initialized and\nregistered during dw_dp_bind(), but are never unregistered, which may\nlead to memory leaks and/or use-after-free:\n\n[  224.661371] BUG: KASAN: slab-use-after-free in device_is_dependent+0xe0/0x2b0\n[  224.662015] Read of size 8 at addr ffff00011aee8550 by task modprobe/658\n[  224.662612]\n[  224.662752] CPU: 7 UID: 0 PID: 658 Comm: modprobe Not tainted 7.0.0-rc2-next-20260305 #14 PREEMPT\n[  224.662759] Hardware name: Radxa ROCK 5B (DT)\n[  224.662762] Call trace:\n[  224.662764]  show_stack+0x20/0x38 (C)\n[  224.662772]  dump_stack_lvl+0x6c/0x98\n[  224.662777]  print_report+0x160/0x4b8\n[  224.662783]  kasan_report+0xb4/0xe0\n[  224.662790]  __asan_report_load8_noabort+0x20/0x30\n[  224.662796]  device_is_dependent+0xe0/0x2b0\n[  224.662802]  device_is_dependent+0x108/0x2b0\n[  224.662808]  device_link_add+0x1f8/0x10b0\n[  224.662813]  devm_of_phy_get_by_index+0x120/0x200\n[  224.662819]  dw_dp_bind+0x34c/0xb10 [dw_dp]\n[  224.662830]  dw_dp_rockchip_bind+0x194/0x250 [rockchipdrm]\n[  224.662864]  component_bind_all+0x3a8/0x720\n[  224.662869]  rockchip_drm_bind+0x120/0x390 [rockchipdrm]\n[  224.662899]  try_to_bring_up_aggregate_device+0x76c/0x838\n[  224.662904]  component_master_add_with_match+0x1f4/0x230\n[  224.662909]  rockchip_drm_platform_probe+0x420/0x538 [rockchipdrm]\n[  224.662939]  platform_probe+0xe8/0x168\n[  224.662945]  really_probe+0x340/0x828\n[  224.662950]  __driver_probe_device+0x2e0/0x350\n[  224.662954]  driver_probe_device+0x80/0x140\n[  224.662959]  __driver_attach+0x398/0x460\n[  224.662964]  bus_for_each_dev+0xe0/0x198\n[  224.662968]  driver_attach+0x50/0x68\n[  224.662972]  bus_add_driver+0x2a0/0x4c0\n[  224.662977]  driver_register+0x294/0x360\n[  224.662982]  __platform_driver_register+0x7c/0x98\n[  224.662987]  rockchip_drm_init+0xc4/0xff8 [rockchipdrm]\n\nSince a previous commit exported dw_dp_unbind() function in DW DP core\nlibrary to take care of the necessary cleanup, use this in the\ncomponent's unbind() callback, as well as in its bind() error path.","Type":"Description","Title":"drm/rockchip: dw_dp: Release core resources"}]}}}