Impact
A memory leak occurs in the Linux kernel’s DRM subsystem when a page‑flip event is signaled during an atomic commit that uses a sw_sync fence. If the event is allocated in prepare_signaling() it is cleared in complete_signaling() without dropping its reference, allowing drm_crtc_commit to be leaked into __drm_atomic_helper_crtc_destroy_state(). The leak can be reproduced by signaling a thread that is executing DRM_MODE_PAGE_FLIP_EVENT and causing the ioctl to block at drm_atomic_helper_wait_for_fences(). Repeated exploitation can exhaust kernel memory and trigger a denial‑of‑service. This is a classic resource‑leak flaw corresponding to CWE‑911.
Affected Systems
Any Linux kernel that has not incorporated the patch on the relevant DRM drivers. The issue appears in the AMDGPU and VKMS drivers and applies to all distributions that ship the affected kernel versions.
Risk and Exploitability
The EPSS score is less than 1 % and the vulnerability is not in the CISA KEV catalogue, indicating a low probability of widespread exploitation. With a CVSS score of 5.5, this vulnerability is considered of moderate severity, and the flaw can be triggered from user space by emitting DRM_MODE_PAGE_FLIP_EVENT signals and sw_sync fences, leading to a memory‑exhaustion denial of service on a running system. Since no public exploit has been reported, the immediate risk is moderate; prompt remediation is still advised.
OpenCVE Enrichment
Debian DLA
Debian DSA