Description
In the Linux kernel, the following vulnerability has been resolved:

drm: fix race between partial drm_dev_register() failure and ioctl

If drm_dev_register() fails after registering a minor (e.g. render minor
registered, primary minor fails), userspace could have opened the first
minor and entered a drm_dev_enter() critical section. Since the
unplugged flag was never set, the ioctl proceeds while the error path
tears down device resources.

Fix this by introducing drm_dev_synchronize_unplug(), which sets the
unplugged flag and waits for the SRCU barrier, ensuring all in-flight
drm_dev_enter() critical sections complete before cleanup proceeds; call
it on the error path of drm_dev_register().
Published: 2026-09-16
Score: 7.8 High
EPSS: < 1% Very Low
KEV: No
Impact: Race condition that can cause kernel memory corruption or crash
Action: Immediate Patch
AI Analysis

Impact

In the DRM subsystem of the Linux kernel, a race condition exists when the device registration routine partially fails after partially registering a minor number. A user‑space process can open the device that is still considered live, enter a critical section, and then the kernel begins to tear down the device resources. Because the unplug flag is never cleared, the ioctl that follows may act on resources that are in the process of being deallocated, which can corrupt kernel memory or lead to a crash.

Affected Systems

The vulnerability applies to any Linux kernel build that contains the unpatched drm_dev_register path. The specific kernel releases that are affected are not enumerated in the advisory, and the fix is introduced in later commits. Therefore, any kernel version that predates the commit introducing drm_dev_synchronize_unplug() is potentially vulnerable.

Risk and Exploitability

The CVSS score of 7.8 marks this as high severity. The EPSS score of less than 1% indicates a low probability of widescale exploitation, and the issue is not listed in the CISA KEV catalog. The likely attack vector involves a local user triggering a failed device registration and then invoking an ioctl on the partially registered device. No documented remote exploitation pathway exists.

Generated by OpenCVE AI on September 18, 2026 at 09:55 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Apply a kernel update that incorporates the drm_dev_synchronize_unplug() fix
  • Reboot the system to load the updated kernel and ensure the DRM subsystem is restarted
  • If using a custom kernel, cherry‑pick the commits that add drm_dev_synchronize_unplug() and rebuild

Generated by OpenCVE AI on September 18, 2026 at 09:55 UTC.

Tracking

Sign in to view the affected projects.

Advisories
Source ID Title
Debian DLA Debian DLA DLA-4817-1 linux-6.12 security update
Debian DSA Debian DSA DSA-6528-1 linux security update
History

Fri, 18 Sep 2026 10:15:00 +0000

Type Values Removed Values Added
Weaknesses CWE-362

Wed, 16 Sep 2026 14:45:00 +0000

Type Values Removed Values Added
Metrics cvssV3_1

{'score': 7.8, 'vector': 'CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H'}


Wed, 16 Sep 2026 10:45:00 +0000

Type Values Removed Values Added
Description In the Linux kernel, the following vulnerability has been resolved: drm: fix race between partial drm_dev_register() failure and ioctl If drm_dev_register() fails after registering a minor (e.g. render minor registered, primary minor fails), userspace could have opened the first minor and entered a drm_dev_enter() critical section. Since the unplugged flag was never set, the ioctl proceeds while the error path tears down device resources. Fix this by introducing drm_dev_synchronize_unplug(), which sets the unplugged flag and waits for the SRCU barrier, ensuring all in-flight drm_dev_enter() critical sections complete before cleanup proceeds; call it on the error path of drm_dev_register().
Title drm: fix race between partial drm_dev_register() failure and ioctl
First Time appeared Linux
Linux linux Kernel
CPEs cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*
Vendors & Products Linux
Linux linux Kernel
References

Subscriptions

Linux Linux Kernel
cve-icon MITRE

Status: PUBLISHED

Assigner: Linux

Published:

Updated: 2026-09-16T14:39:02.220Z

Reserved: 2026-09-11T19:38:34.768Z

Link: CVE-2026-89823

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Received

Published: 2026-09-16T11:16:48.850

Modified: 2026-09-16T15:18:11.300

Link: CVE-2026-89823

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-18T10:00:06Z

Weaknesses
  • CWE-362

    Concurrent Execution using Shared Resource with Improper Synchronization ('Race Condition')