SB2026040657 - Use-after-free in Linux kernel gpu drm driver
Published: April 6, 2026
Breakdown by Severity
- Low
- Medium
- High
- Critical
Description
This security bulletin contains information about 1 security vulnerability.
1) Use-after-free (CVE-ID: CVE-2026-23471)
The vulnerability allows a local user to cause a denial of service.
The vulnerability exists due to use-after-free in framebuffers and property blobs in the drm subsystem when calling drm_dev_unplug during device unbind and file close handling. A local user can trigger device unbind operations and subsequent cleanup to cause a denial of service.
The issue was observed with freed pointer dereferences, warnings, and a general protection fault after compositor exit. Exploitation requires local access and interaction with the affected DRM device lifecycle.
Remediation
Install update from vendor's website.
References
- https://git.kernel.org/stable/c/074d06d3724ccab0c5bb779db594a82b6405e501
- https://git.kernel.org/stable/c/54df178324b268c62f847381e2813a1b0f971384
- https://git.kernel.org/stable/c/6bee098b91417654703e17eb5c1822c6dfd0c01d
- https://git.kernel.org/stable/c/7e3ec3bf4015156dcc5bafed13f26a587cc37f5c
- https://git.kernel.org/stable/c/e493c135980f90c20308d1a98f2e0d1223951e94
- https://git.kernel.org/stable/c/eec4d5758f33925e0bdb4a32b45d86a68afa4516