Description
In the Linux kernel, the following vulnerability has been resolved:

drm: Fix drm_crtc_commit leak if signaled when PAGE_FLIP_EVENT is used

Commit 1c6ceeee6ebb ("drm/atomic: Fix memleak on ERESTARTSYS during
non-blocking commits") fixed a very similar issue when the event was
allocated by drm_atomic_helper_setup_commit() itself.

However, if the event is allocated in prepare_signaling(), it will also be
set to NULL in complete_signaling(), which prevents drm_crtc_commit from
being put in __drm_atomic_helper_crtc_destroy_state().

Dropping the reference when the event is set to NULL at
complete_signaling() fixes the leak.

The leak can be reproduced by sending a signal to the thread using
DRM_MODE_PAGE_FLIP_EVENT and using a sw_sync fence to cause the atomic
ioctl to block at drm_atomic_helper_wait_for_fences(). It happened both
with amdgpu and vkms.
Published: 2026-09-16
Score: 5.5 Medium
EPSS: < 1% Very Low
KEV: No
Impact: Memory leak leading to denial of service
Action: Patch Now
AI Analysis

Impact

A memory leak occurs in the Linux kernel’s DRM subsystem when a page‑flip event is signaled during an atomic commit that uses a sw_sync fence. If the event is allocated in prepare_signaling() it is cleared in complete_signaling() without dropping its reference, allowing drm_crtc_commit to be leaked into __drm_atomic_helper_crtc_destroy_state(). The leak can be reproduced by signaling a thread that is executing DRM_MODE_PAGE_FLIP_EVENT and causing the ioctl to block at drm_atomic_helper_wait_for_fences(). Repeated exploitation can exhaust kernel memory and trigger a denial‑of‑service. This is a classic resource‑leak flaw corresponding to CWE‑911.

Affected Systems

Any Linux kernel that has not incorporated the patch on the relevant DRM drivers. The issue appears in the AMDGPU and VKMS drivers and applies to all distributions that ship the affected kernel versions.

Risk and Exploitability

The EPSS score is less than 1 % and the vulnerability is not in the CISA KEV catalogue, indicating a low probability of widespread exploitation. With a CVSS score of 5.5, this vulnerability is considered of moderate severity, and the flaw can be triggered from user space by emitting DRM_MODE_PAGE_FLIP_EVENT signals and sw_sync fences, leading to a memory‑exhaustion denial of service on a running system. Since no public exploit has been reported, the immediate risk is moderate; prompt remediation is still advised.

Generated by OpenCVE AI on September 24, 2026 at 01:47 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Apply the kernel patch that clears the event reference properly (commit 1c6ceeee6ebb or any kernel version that includes this fix).
  • Ensure that the AMDGPU or VKMS drivers are updated to a version that includes the patch (e.g., update distro packages or build from source).
  • After patching, monitor system memory usage for any abnormal patterns and verify that no further kernel memory leaks occur.

Generated by OpenCVE AI on September 24, 2026 at 01:47 UTC.

Tracking

Sign in to view the affected projects.

Advisories
Source ID Title
Debian DLA Debian DLA DLA-4817-1 linux-6.12 security update
Debian DSA Debian DSA DSA-6528-1 linux security update
History

Thu, 24 Sep 2026 00:15:00 +0000

Type Values Removed Values Added
Weaknesses CWE-911
References
Metrics threat_severity

None

cvssV3_1

{'score': 5.5, 'vector': 'CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H'}

threat_severity

Low


Wed, 16 Sep 2026 10:45:00 +0000

Type Values Removed Values Added
Description In the Linux kernel, the following vulnerability has been resolved: drm: Fix drm_crtc_commit leak if signaled when PAGE_FLIP_EVENT is used Commit 1c6ceeee6ebb ("drm/atomic: Fix memleak on ERESTARTSYS during non-blocking commits") fixed a very similar issue when the event was allocated by drm_atomic_helper_setup_commit() itself. However, if the event is allocated in prepare_signaling(), it will also be set to NULL in complete_signaling(), which prevents drm_crtc_commit from being put in __drm_atomic_helper_crtc_destroy_state(). Dropping the reference when the event is set to NULL at complete_signaling() fixes the leak. The leak can be reproduced by sending a signal to the thread using DRM_MODE_PAGE_FLIP_EVENT and using a sw_sync fence to cause the atomic ioctl to block at drm_atomic_helper_wait_for_fences(). It happened both with amdgpu and vkms.
Title drm: Fix drm_crtc_commit leak if signaled when PAGE_FLIP_EVENT is used
First Time appeared Linux
Linux linux Kernel
CPEs cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*
Vendors & Products Linux
Linux linux Kernel
References

Subscriptions

Linux Linux Kernel
cve-icon MITRE

Status: PUBLISHED

Assigner: Linux

Published:

Updated: 2026-09-16T10:30:49.052Z

Reserved: 2026-09-11T19:38:34.768Z

Link: CVE-2026-89816

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Received

Published: 2026-09-16T11:16:46.837

Modified: 2026-09-16T11:16:46.837

Link: CVE-2026-89816

cve-icon Redhat

Severity : Low

Publid Date: 2026-09-16T00:00:00Z

Links: CVE-2026-89816 - Bugzilla

cve-icon OpenCVE Enrichment

Updated: 2026-09-24T02:00:14Z

Weaknesses
  • CWE-911

    Improper Update of Reference Count