Use-after-free in Linux kernel - CVE-2026-43236
Published: May 7, 2026
Linux kernel
Detailed vulnerability description
The vulnerability allows a local user to cause a denial of service.
The vulnerability exists due to a use-after-free in atmel_hlcdc_plane_atomic_duplicate_state() when handling drm atomic commit operations after duplicating plane state. A local user can close and re-open the device node while another DRM client is still attached to cause a denial of service.
It can be triggered in a scenario where another DRM client such as fbdev remains attached.
How to mitigate CVE-2026-43236
Sources
- https://git.kernel.org/stable/c/549c6db503dbb85dbff4840830971853feac6625
- https://git.kernel.org/stable/c/6404898af86d986db1dbbe06177c143e40652e49
- https://git.kernel.org/stable/c/796e77c14c4c1e2cd36473760fb6cc66c695eb47
- https://git.kernel.org/stable/c/7b4d0fab3ff2c00c6d34e1952c9df5129a826aee
- https://git.kernel.org/stable/c/a205740a7231e967ac77cb731171642901c327af
- https://git.kernel.org/stable/c/ac2d898da5095d46bd1ff8585fdd753d58ad91e7
- https://git.kernel.org/stable/c/bc847787233277a337788568e90a6ee1557595eb
- https://git.kernel.org/stable/c/fd4a4d0711f48a99b25bcd45e00eef8339eff82d