Description
In the Linux kernel, the following vulnerability has been resolved:

drm/amd/display: fix dc_lock leak on GPU reset error paths

On GPU reset, dm_suspend() takes dc_lock and leaves it for dm_resume()
to drop. If amdgpu_dm_commit_zero_streams() or dm_dmub_hw_init() fails,
the function returns with the lock still held. The matching resume path
is then skipped, so every later dc_lock take hangs.

Release the cached DC state and unlock before returning the error.
Published: 2026-09-16
Score: 5.5 Medium
EPSS: < 1% Very Low
KEV: No
Impact: Denial of Service via GPU lock deadlock
Action: Patch
AI Analysis

Impact

In the Linux kernel, the AMD display driver contains a flaw where the dc_lock is taken during a GPU reset and is not released if certain error paths are taken. When the lock remains held, subsequent attempts to acquire it block forever, halting GPU operations and any application that depends on graphics. This results in a kernel‑level deadlock that effectively renders the GPU unusable until a system reboot, causing a denial of service for graphical sessions. The vulnerability is identified as a resource leak involving an exclusive lock, grouped under CWE-772.

Affected Systems

All Linux kernel versions that include the AMD display driver but lack the patch are affected. Because the vulnerability is in the kernel’s DRM subsystem, every distribution shipping the stock kernel prior to the merge of the fix is vulnerable. The exact affected build series cannot be determined from the data, but any kernel lacking the commit that releases the dc_lock on error paths is impacted.

Risk and Exploitability

The vulnerability is a resource leak involving the dc_lock in the AMD display driver. When the kernel attempts a GPU reset and certain initialization functions fail, the lock is never released. This means any subsequent attempt to acquire the lock blocks indefinitely, effectively disabling all further GPU activity and causing a graphical system hang. The CVE description does not specify how to trigger the error path, and no attack vector is explicitly documented. It is reasonable to infer that the flaw would be exercised during normal kernel operation when a GPU reset occurs or if an error in the driver path is triggered, but this inference is not confirmed by the advisory. The CVSS score of 5.5 indicates medium severity, and the EPSS score of less than 1% suggests a low probability of exploitation. The vulnerability is not listed in the CISA KEV catalog.

Generated by OpenCVE AI on September 24, 2026 at 03:54 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Upgrade the Linux kernel to a version that includes the patched AMD display driver. The fix was merged into the mainline kernel, so installing the latest stable kernel from your distribution will resolve the lock leak.
  • If an immediate kernel upgrade is not possible, download the specific patch from the official kernel patch set referenced in the advisory, apply it to your kernel source tree, rebuild, and install the updated kernel.
  • After updating or patching, verify GPU operation by performing a reset or running a fullscreen graphics application to confirm that the dc_lock is released and that no deadlock occurs.

Generated by OpenCVE AI on September 24, 2026 at 03:54 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Thu, 24 Sep 2026 02:30:00 +0000

Type Values Removed Values Added
Weaknesses CWE-771

Thu, 24 Sep 2026 00:15:00 +0000

Type Values Removed Values Added
Weaknesses CWE-772
References
Metrics threat_severity

None

cvssV3_1

{'score': 5.5, 'vector': 'CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H'}

threat_severity

Low


Fri, 18 Sep 2026 09:30:00 +0000

Type Values Removed Values Added
Weaknesses CWE-771

Wed, 16 Sep 2026 10:45:00 +0000

Type Values Removed Values Added
Description In the Linux kernel, the following vulnerability has been resolved: drm/amd/display: fix dc_lock leak on GPU reset error paths On GPU reset, dm_suspend() takes dc_lock and leaves it for dm_resume() to drop. If amdgpu_dm_commit_zero_streams() or dm_dmub_hw_init() fails, the function returns with the lock still held. The matching resume path is then skipped, so every later dc_lock take hangs. Release the cached DC state and unlock before returning the error.
Title drm/amd/display: fix dc_lock leak on GPU reset error paths
First Time appeared Linux
Linux linux Kernel
CPEs cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*
Vendors & Products Linux
Linux linux Kernel
References

Subscriptions

Linux Linux Kernel
cve-icon MITRE

Status: PUBLISHED

Assigner: Linux

Published:

Updated: 2026-09-16T10:30:52.803Z

Reserved: 2026-09-11T19:38:34.768Z

Link: CVE-2026-89820

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Received

Published: 2026-09-16T11:16:47.383

Modified: 2026-09-16T11:16:47.383

Link: CVE-2026-89820

cve-icon Redhat

Severity : Low

Publid Date: 2026-09-16T00:00:00Z

Links: CVE-2026-89820 - Bugzilla

cve-icon OpenCVE Enrichment

Updated: 2026-09-24T04:00:13Z

Weaknesses
  • CWE-772

    Missing Release of Resource after Effective Lifetime