SB20260406109 - Missing Release of Resource after Effective Lifetime in Linux kernel drm logicvc driver
Published: April 6, 2026
Breakdown by Severity
- Low
- Medium
- High
- Critical
Description
This security bulletin contains information about 1 security vulnerability.
1) Missing Release of Resource after Effective Lifetime (CVE-ID: CVE-2026-23426)
The vulnerability allows a local user to cause a denial of service.
The vulnerability exists due to a device node reference leak in logicvc_drm_config_parse() when parsing the "layers" node from the device tree. A local user can trigger the vulnerable code path to cause a denial of service.
The issue results from a missing release of the reference returned by of_get_child_by_name(). No user interaction is required.
Remediation
Install update from vendor's website.
References
- https://git.kernel.org/stable/c/0bd326dffd9e103335d77d9c31275c0d5a7979eb
- https://git.kernel.org/stable/c/78e91e49d28e05ccaa6b445bafb5e367d57c9583
- https://git.kernel.org/stable/c/871630255ecd2d9b64ad1d75a7dfc0567d7d9989
- https://git.kernel.org/stable/c/b88f49910be147b7974098b9172b0d3873142d6a
- https://git.kernel.org/stable/c/f8a6eba20edb938166b26e133cc61306e1bc6de9
- https://git.kernel.org/stable/c/fef0e649f8b42bdffe4a916dd46e1b1e9ad2f207