SB20260917140 - Race condition in Linux kernel gpu drm driver
Published: September 17, 2026
Breakdown by Severity
- Low
- Medium
- High
- Critical
Description
This security bulletin contains information about 1 vulnerability.
1) Race condition (CVE-ID: CVE-2026-89823)
CWE-ID: CWE-362 - Concurrent Execution using Shared Resource with Improper Synchronization ('Race Condition')
CVSSv4: 8.5 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]
The vulnerability allows a local user to compromise confidentiality, integrity, and availability.
The vulnerability exists due to a race condition in drm_dev_register() error handling when a partially registered DRM minor is opened and an ioctl is processed. A local user can open the registered minor and issue an ioctl while device resources are being torn down to compromise confidentiality, integrity, and availability.
Remediation
Install update from vendor's website.
References
- https://git.kernel.org/stable/c/19dbfe4d586aecfed121cb3fa62281761d9d341f
- https://git.kernel.org/stable/c/24d28d15c0f7f7d4a1c229f8730314f0f8758810
- https://git.kernel.org/stable/c/26d9162213952927cd59c0d94b7e0e992b347bec
- https://git.kernel.org/stable/c/2d1215a72159d00001e08dee162e27718934bee9
- https://git.kernel.org/stable/c/6729990df9e70623bf53f855b521ae71ca9cb278
- https://git.kernel.org/stable/c/79d09cfe90304ff4f195e47d569800f5e0f8b854
- https://git.kernel.org/stable/c/a0a7e2e177f2f18b9e7318a4c64ac44efd9ef22c
- https://git.kernel.org/stable/c/eb197f7d60f00d0f5b1b3505dfc86a7e36045a3e