Improper Initialization in Linux kernel - CVE-2026-43477
Published: May 14, 2026
Linux kernel
Detailed vulnerability description
The vulnerability allows a local user to cause a denial of service.
The vulnerability exists due to improper hardware register initialization order in the i915 VRR timing configuration logic when handling failed display link training. A local user can trigger display configuration involving VRR after a link training failure to cause a denial of service.
The issue was observed on ICL systems with an external display connected through a dock using a faulty type-C cable, while TGL systems appeared unaffected.