Description
In the Linux kernel, the following vulnerability has been resolved:

fbdev: omapfb: panel-dsi-cm: initialize lock before registering display

dsicm_probe() registers the display before initializing ddata->lock.
Once omapdss_register_display() publishes the display, another consumer
can reach a dsicm callback that takes this mutex while it is still
uninitialized.

Initialize the mutex before registering the display so the published
callbacks always see a valid lock.
Published: 2026-09-11
Score: 8.4 High
EPSS: < 1% Very Low
KEV: No
Impact: Kernel Crash
Action: Patch Now
AI Analysis

Impact

A race condition in the Linux kernel’s fbdev omapfb panel DSI CM driver allows a driver to register a display before initializing the mutex that protects its callback data. When another component invokes a callback during registration, it may acquire this uninitialized lock, leading to undefined behavior and a kernel crash. The flaw is identified as CWE-908, a race condition.

Affected Systems

The vulnerability affects all Linux kernel builds that include the unpatched omapfb panel DSI CM driver. The publicly available information does not list specific kernel versions, so any kernel containing the unmodified driver code prior to the patch is considered vulnerable.

Risk and Exploitability

The high‑severity CVSS score of 8.4 indicates significant impact. The EPSS score of less than 1% reflects a low probability of exploitation, and the flaw is not present in the CISA KEV catalog. Based on the description, the likely attack vector is a local or privileged user capable of loading or interacting with the omapfb driver, potentially causing a denial of service through kernel crash.

Generated by OpenCVE AI on September 15, 2026 at 21:28 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Upgrade the kernel to a version that incorporates the upstream patch for the omapfb driver.
  • If a vendor update is unavailable, apply the commit that initializes the lock before registration to the driver source and rebuild the kernel.
  • As a temporary defense, disable or blacklist the omapfb module to prevent exposure of the uninitialized lock.

Generated by OpenCVE AI on September 15, 2026 at 21:28 UTC.

Tracking

Sign in to view the affected projects.

Advisories
Source ID Title
Debian DSA Debian DSA DSA-6528-1 linux security update
History

Mon, 14 Sep 2026 12:30:00 +0000


Sun, 13 Sep 2026 06:45:00 +0000

Type Values Removed Values Added
Metrics cvssV3_1

{'score': 5.5, 'vector': 'CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H'}

cvssV3_1

{'score': 8.4, 'vector': 'CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H'}


Sat, 12 Sep 2026 00:15:00 +0000

Type Values Removed Values Added
Weaknesses CWE-908
References
Metrics threat_severity

None

cvssV3_1

{'score': 5.5, 'vector': 'CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H'}

threat_severity

Moderate


Fri, 11 Sep 2026 23:45:00 +0000

Type Values Removed Values Added
Description In the Linux kernel, the following vulnerability has been resolved: fbdev: omapfb: panel-dsi-cm: initialize lock before registering display dsicm_probe() registers the display before initializing ddata->lock. Once omapdss_register_display() publishes the display, another consumer can reach a dsicm callback that takes this mutex while it is still uninitialized. Initialize the mutex before registering the display so the published callbacks always see a valid lock.
Title fbdev: omapfb: panel-dsi-cm: initialize lock before registering display
First Time appeared Linux
Linux linux Kernel
CPEs cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*
Vendors & Products Linux
Linux linux Kernel
References

Subscriptions

Linux Linux Kernel
cve-icon MITRE

Status: PUBLISHED

Assigner: Linux

Published:

Updated: 2026-09-14T12:01:22.440Z

Reserved: 2026-09-11T19:38:34.731Z

Link: CVE-2026-89599

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Received

Published: 2026-09-11T20:19:44.733

Modified: 2026-09-14T13:19:14.150

Link: CVE-2026-89599

cve-icon Redhat

Severity : Moderate

Publid Date: 2026-09-11T19:45:02Z

Links: CVE-2026-89599 - Bugzilla

cve-icon OpenCVE Enrichment

Updated: 2026-09-15T21:30:16Z

Weaknesses
  • CWE-908

    Use of Uninitialized Resource