SB20260917141 - Missing Release of Resource after Effective Lifetime in Linux kernel drm panel driver
Published: September 17, 2026
Breakdown by Severity
- Low
- Medium
- High
- Critical
Description
This security bulletin contains information about 1 vulnerability.
1) Missing Release of Resource after Effective Lifetime (CVE-ID: CVE-2026-89824)
CWE-ID: CWE-772 - Missing Release of Resource after Effective Lifetime
CVSSv4: 4.6 [CVSS:4.0/AV:L/AC:L/AT:N/PR:H/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N]
The vulnerability allows a local privileged user to cause a resource leak.
The vulnerability exists due to a missing release of an i2c adapter reference in the drm/panel-edp panel driver when handling probe failures or driver unbinding with a devicetree ddc-i2c-bus property referring to the auxiliary ddc bus. A local privileged user can cause a panel driver probe failure or unbind to cause a resource leak.
Remediation
Install update from vendor's website.
References
- https://git.kernel.org/stable/c/0259846b15a665c6762a86b3fa0eb8b674b35d1c
- https://git.kernel.org/stable/c/8d9e6dffaea9b1282f8dc82f2d5e3cbd64e11fb3
- https://git.kernel.org/stable/c/972afe6d5314037556bf6b3e635d7a06547064ee
- https://git.kernel.org/stable/c/e048a11cf4649e03f194e16eb809e57ffc9eb5b6
- https://git.kernel.org/stable/c/e2a9e291275a74e309a21cbb1def6296a72d6aed
- https://git.kernel.org/stable/c/f933d0f6fcd6280ce709553d394c30e9f7cc1b8c