SB20260406109 - Missing Release of Resource after Effective Lifetime in Linux kernel drm logicvc driver



SB20260406109 - Missing Release of Resource after Effective Lifetime in Linux kernel drm logicvc driver

Published: April 6, 2026

Security Bulletin ID SB20260406109
Severity
Low
Patch available
YES
Number of vulnerabilities 1
Exploitation vector Local access
Highest impact Denial of service

Breakdown by Severity

Low 100%
  • Low
  • Medium
  • High
  • Critical

Description

This security bulletin contains information about 1 security vulnerability.


1) Missing Release of Resource after Effective Lifetime (CVE-ID: CVE-2026-23426)

The vulnerability allows a local user to cause a denial of service.

The vulnerability exists due to a device node reference leak in logicvc_drm_config_parse() when parsing the "layers" node from the device tree. A local user can trigger the vulnerable code path to cause a denial of service.

The issue results from a missing release of the reference returned by of_get_child_by_name(). No user interaction is required.


Remediation

Install update from vendor's website.